Open mend-for-github-com[bot] opened 4 years ago
:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.
:information_source: This issue was automatically re-opened by WhiteSource because the vulnerable library in the specific branch(es) has been detected in the WhiteSource inventory.
CVE-2018-20835 - High Severity Vulnerability
Vulnerable Library - node6be96c70f5642ac07b9f505f464f958245df03d0
Node.js JavaScript runtime :sparkles::turtle::rocket::sparkles:
Library home page: https://github.com/nodejs/node.git
Found in HEAD commit: b011a55ee3bfce5d2fedf4fd780e4196d446c504
Found in base branch: gh-pages
Vulnerable Source Files (1)
Vulnerability Details
A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.
Publish Date: 2019-04-30
URL: CVE-2018-20835
CVSS 3 Score Details (7.5)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: High - Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://hackerone.com/reports/344595
Release Date: 2019-04-30
Fix Resolution: v1.16.2