logo

CVE-2020-12265 decompress-tar

Package

Manager: npm
Name: decompress-tar
Vulnerable Version: >=0 <=4.1.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

EPSS: N/A pctlN/A

Details

Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip). It is possible to bypass the security measures provided by decompress and conduct ZIP path traversal through symlinks.

Metadata

Created:
Modified:
Source: MANUAL
CWE IDs: ["CWE-29"]
Alternative ID: N/A
Finding: F063
Auto approve: 1