Description
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
Remediation
References
https://github.com/kevva/decompress/issues/71
https://github.com/kevva/decompress/pull/73
https://www.npmjs.com/advisories/1217
Related Vulnerabilities
CVE-2021-33604 Vulnerability in maven package com.vaadin:flow-server
CVE-2022-43430 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2019-5415 Vulnerability in npm package serve
CVE-2019-15954 Vulnerability in npm package total.js
CVE-2021-4279 Vulnerability in maven package org.webjars.npm:fast-json-patch