Description
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Remediation
References
https://nodesecurity.io/advisories/57
http://www.openwall.com/lists/oss-security/2016/04/20/11
Related Vulnerabilities
CVE-2017-17068 Vulnerability in npm package auth0-js
CVE-2022-4111 Vulnerability in npm package tooljet
CVE-2023-33265 Vulnerability in maven package com.hazelcast:hazelcast
CVE-2023-22457 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-plugins
CVE-2022-21803 Vulnerability in maven package org.webjars.npm:nconf