5
CVSSv2

CVE-2015-8860

Published: 23/01/2017 Updated: 24/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The tar package prior to 2.0.0 for Node.js allows remote malicious users to write to arbitrary files via a symlink attack in an archive.

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs node.js

Vendor Advisories

A flaw was found in the way nodejs-tar, a Nodejs module for reading and writing of tar archives, handled symbolic links when processing NPM packages An attacker could potentially use this flaw to rewrite arbitrary files on the system ...