Description
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Remediation
References
http://www.openwall.com/lists/oss-security/2016/04/20/11
https://nodesecurity.io/advisories/57
Related Vulnerabilities
CVE-2022-39250 Vulnerability in npm package matrix-js-sdk
CVE-2022-36888 Vulnerability in maven package com.datapipe.jenkins.plugins:hashicorp-vault-plugin
CVE-2017-14063 Vulnerability in maven package org.asynchttpclient:async-http-client-project
CVE-2022-21700 Vulnerability in maven package io.micronaut:micronaut-http
CVE-2022-43422 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-utilities