MGASA-2022-0103

Advisory lineage Upstream: 4 Downstream: 0
Published: 21 Mar 2022, 20:18
Last modified:16 Apr 2026, 04:41

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Mar 2022, 20:18
Published
Vulnerability first disclosed
16 Apr 2026, 04:41
Last Modified
Vulnerability information updated

Description

Updated nodejs-tar packages fix security vulnerability Untrusted tar file to symlink into an arbitrary location allowing file overwrites. (CVE-2021-37712) Arbitrary file creation/overwrite and arbitrary code execution. (CVE-2021-37701) Arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. (CVE-2021-32803) Arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization (CVE-2021-32804)

Affected Systems

  • mageianodejs-tar

    < 6.0.5-1.1.mga8

References (3)