QID 981084
QID 981084: Nodejs (npm) Security Update for tar (GHSA-gfjr-3jmm-4g9v)
Versions of `tar` prior to 2.0.0 are affected by an arbitrary file write vulnerability. The vulnerability occurs because `tar` does not verify that extracted symbolic links to not resolve to targets outside of the extraction root directory.
## Recommendation
Update to version 2.0.0 or later
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gfjr-3jmm-4g9v for updates pertaining to this vulnerability.
Vendor References
- GHSA-gfjr-3jmm-4g9v -
github.com/advisories/GHSA-gfjr-3jmm-4g9v
CVEs related to QID 981084
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gfjr-3jmm-4g9v | tar |
|