Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg4NHctNjk4Zi05Mjdm
Arbitrary File Write via Archive Extraction in unzipper
Versions of unzipper
before 0.8.13 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (../../file.txt
for example).
Recommendation
Update to version 0.3.18 or later.
Permalink: https://github.com/advisories/GHSA-884w-698f-927fJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg4NHctNjk4Zi05Mjdm
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 6 years ago
Updated: about 1 year ago
CVSS Score: 5.5
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Identifiers: GHSA-884w-698f-927f, CVE-2018-1002203
References:
- https://nvd.nist.gov/vuln/detail/CVE-2018-1002203
- https://github.com/ZJONSSON/node-unzipper/pull/59
- https://hackerone.com/reports/362119
- https://github.com/advisories/GHSA-884w-698f-927f
- https://snyk.io/research/zip-slip-vulnerability
- https://www.npmjs.com/advisories/680
- https://github.com/ZJONSSON/node-unzipper/commit/2220ddd5b58f6252069a4f99f9475441ad0b50cd
- https://github.com/snyk/zip-slip-vulnerability
- https://snyk.io/vuln/npm:unzipper:20180415
Blast Radius: 26.2
Affected Packages
npm:unzipper
Dependent packages: 1,409Dependent repositories: 57,867
Downloads: 13,278,937 last month
Affected Version Ranges: < 0.8.13
Fixed in: 0.8.13
All affected versions: 0.1.11, 0.2.0, 0.3.0, 0.3.1, 0.3.2, 0.4.0, 0.4.1, 0.5.0, 0.6.0, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.8.6, 0.8.7, 0.8.8, 0.8.9, 0.8.11, 0.8.12
All unaffected versions: 0.8.13, 0.8.14, 0.9.0, 0.9.1, 0.9.2, 0.9.3, 0.9.4, 0.9.5, 0.9.6, 0.9.7, 0.9.8, 0.9.9, 0.9.10, 0.9.11, 0.9.12, 0.9.13, 0.9.14, 0.9.15, 0.10.0, 0.10.1, 0.10.2, 0.10.3, 0.10.4, 0.10.5, 0.10.6, 0.10.7, 0.10.8, 0.10.9, 0.10.10, 0.10.11, 0.10.14, 0.11.2, 0.11.3, 0.11.4, 0.11.5, 0.11.6, 0.12.1, 0.12.2, 0.12.3