Description
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Remediation
References
http://www.openwall.com/lists/oss-security/2016/04/20/11
https://nodesecurity.io/advisories/57
Related Vulnerabilities
CVE-2021-23341 Vulnerability in maven package org.webjars.npm:prismjs
CVE-2020-15168 Vulnerability in npm package node-fetch
CVE-2019-6286 Vulnerability in npm package node-sass
CVE-2019-1003059 Vulnerability in maven package org.jvnet.hudson.plugins:ftppublisher
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oauth-core-api