CVE-2018-20834
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
- Affected products
- Node-Tar
- Isaacs Tar
- < 2.2.2, 4.4.2
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 3.1% (87th percentile)
- Weakness
- CWE-59
- NVD status
- Modified
- Published
- 2019-04-30
CVE-2018-20834 at NVD
No indexed exploits for CVE-2018-20834 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-20834 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.