QID 376659
Date Published: 2022-06-15
QID 376659: W-ZIP NPM Package Path Traversal Vulnerability
The package w-zip versions prior to 1.0.12 are vulnerable to Path Traversal Vulnerability.
Affected Versions:
w-zip versions prior to 1.0.12
QID detection logic(Authenticated): This QID checks for vulnerable versions of w-zip package using the npm list -g command.
Note: w-zip is a npm package that can be installed as a global, developer and production dependency. We can only detect w-zip package if it is installed globally(as a global dependency). This QID checks for vulnerable version of w-zip at default location only.
Successful exploitation of this vulnerability may lead to Information Disclosure/Denial of Service/Remote Code Execution.
Solution
Customers are requested to update to w-zip version greater than 1.0.12. For more information please refer to NPM w-zip
Vendor References
- NPM w-zip -
github.com/advisories/GHSA-fr6q-jv7j-35g3
CVEs related to QID 376659
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| w-zip |
|