MEDIUM
unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction
Published Jul 25, 2018
5.5
MEDIUMCVSS 3.0
EPSS 10.55%
Description
unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
Affected products
-
Affected
- ≥ unspecified, < 0.8.13
- < 0.8.13
No data.
No Red Hat product state for this CVE.
unzipper
npm
Introduced 0 Fixed 0.8.13
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | unzipper | 0 | 0.8.13 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0248 Advisory
- https://github.com/ZJONSSON/node-unzipper/commit/2220ddd5b58f6252069a4f99f9475441ad0b50cd x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/ZJONSSON/node-unzipper/pull/59 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-884w-698f-927f Advisory
- https://github.com/snyk/zip-slip-vulnerability x_refsource_MISCExploitThird Party Advisory
- https://hackerone.com/reports/362119
- https://nvd.nist.gov/vuln/detail/CVE-2018-1002203
- https://snyk.io/research/zip-slip-vulnerability x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://snyk.io/vuln/npm:unzipper:20180415 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://www.npmjs.com/advisories/680
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0248 | Advisory | |
| https://github.com/ZJONSSON/node-unzipper/commit/2220ddd5b58f6252069a4f99f9475441ad0b50cd | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://github.com/ZJONSSON/node-unzipper/pull/59 | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-884w-698f-927f | Advisory | |
| https://github.com/snyk/zip-slip-vulnerability | x_refsource_MISCExploitThird Party Advisory | |
| https://hackerone.com/reports/362119 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-1002203 | ||
| https://snyk.io/research/zip-slip-vulnerability | x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory | |
| https://snyk.io/vuln/npm:unzipper:20180415 | x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory | |
| https://www.npmjs.com/advisories/680 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jul 25, 2018
Updated Sep 16, 2024
Reserved Jul 25, 2018
Link CVE-2018-1002203
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-884W-698F-927F