Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update current vulnerable version of tar #127

Open
TyrealGray opened this issue May 5, 2019 · 1 comment
Open

Update current vulnerable version of tar #127

TyrealGray opened this issue May 5, 2019 · 1 comment
Assignees

Comments

@TyrealGray
Copy link

See here https://nvd.nist.gov/vuln/detail/CVE-2018-20834

@kraenhansen
Copy link

kraenhansen commented Nov 3, 2022

I can verify this is still an issue.
This is the output from running npm audit in a repository with the latest version of nw-gyp installed:

tar  <=4.4.17
Severity: high
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization - https://github.com/advisories/GHSA-5955-9wpr-37jh
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links - https://github.com/advisories/GHSA-qq89-hq3f-393p
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links - https://github.com/advisories/GHSA-9r2w-394v-53qc
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization - https://github.com/advisories/GHSA-3jfq-g458-7qm9
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning - https://github.com/advisories/GHSA-r628-mhmh-qjhw
No fix available
node_modules/tar
  nw-gyp  *
  Depends on vulnerable versions of tar
  node_modules/nw-gyp

2 high severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.

I verified that the latest version of node-gyp doesn't have this and I'd think a rebase is in due time.

@rogerwang rogerwang self-assigned this Nov 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants