MGASA-2022-0103
Advisory lineage Upstream: 4 Downstream: 0
Published: 21 Mar 2022, 20:18
Last modified:16 Apr 2026, 04:41
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
21 Mar 2022, 20:18
Published
Vulnerability first disclosed
16 Apr 2026, 04:41
Last Modified
Vulnerability information updated
Description
Updated nodejs-tar packages fix security vulnerability Untrusted tar file to symlink into an arbitrary location allowing file overwrites. (CVE-2021-37712) Arbitrary file creation/overwrite and arbitrary code execution. (CVE-2021-37701) Arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. (CVE-2021-32803) Arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization (CVE-2021-32804)
Affected Systems
- mageia•nodejs-tar
< 6.0.5-1.1.mga8