nodejs-tar: Arbitrary file overwrites when extracting tarballs containing a hard-link
Published Apr 30, 2019
8.8
HIGHCVSS 3.0
EPSS 3.15%
Description
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
Affected products
No data.
No data.
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-nodejs-0:8.16.0-1.el7
Fixed · RHSA-2019:1821
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-nodejs8-nodejs-0:8.16.0-1.el7
Fixed · RHSA-2019:1821
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs8-nodejs-0:8.16.0-1.el7
Fixed · RHSA-2019:1821
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs8-nodejs-0:8.16.0-1.el7
Fixed · RHSA-2019:1821
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
Red Hat Enterprise Linux 8
nodejs:10/nodejs
Not affected
Red Hat Mobile Application Platform 4
nodejs-tar
Not affected
Red Hat OpenShift Container Platform 3.10
kibana
Not affected
Red Hat OpenShift Container Platform 3.11
kibana
Not affected
Red Hat OpenShift Container Platform 3.6
kibana
Not affected
Red Hat OpenShift Container Platform 3.7
kibana
Not affected
Red Hat OpenShift Container Platform 3.9
kibana
Not affected
Red Hat OpenShift Container Platform 4
kibana
Not affected
Red Hat Software Collections
rh-nodejs10-nodejs
Not affected
Red Hat Software Collections
rh-nodejs6-nodejs-tar
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-nodejs-0:8.16.0-1.el7 | Fixed | RHSA-2019:1821 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-nodejs8-nodejs-0:8.16.0-1.el7 | Fixed | RHSA-2019:1821 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs8-nodejs-0:8.16.0-1.el7 | Fixed | RHSA-2019:1821 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs8-nodejs-0:8.16.0-1.el7 | Fixed | RHSA-2019:1821 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:10/nodejs | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | nodejs-tar | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.6 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs10-nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs6-nodejs-tar | Not affected | n/a |
tar
npm
Introduced 3.0.0 Fixed 4.4.2tar
npm
Introduced 0 Fixed 2.2.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | tar | 3.0.0 | 4.4.2 |
| npm | tar | 0 | 2.2.2 |
Remediation
Red Hat statement
In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container bundles many nodejs packages as a build time dependencies, including the tar package. The vulnerable nodejs tar package is not used in a way that makes this vulnerability exploitable, hence the impact to OpenShift Logging by this vulnerability is Low.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.15% (0.03145) | 87.49th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.15% (0.03145) | 86.21th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.57% (0.00566) | 65.83th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.88% (0.01875) | 72.11th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.57% (0.00566) | 66.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.39% (0.00385) | 73.96th | v3 (v2023.03.01) |
| Apr 23, 2024 | 0.32% (0.00320) | 70.28th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.34% (0.00339) | 70.57th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.34% (0.00339) | 66.78th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.11% (0.01108) | 29.61th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.66% (0.01659) | 34.20th | v1 |
| Jan 6, 2022 | 1.66% (0.01659) | 33.50th | v1 |
| Sep 1, 2021 | 1.66% (0.01659) | 73.96th | v1 |
| Apr 14, 2021 | 1.66% (0.01659) | 0.00th | v1 |
References (11)
- https://access.redhat.com/errata/RHSA-2019:1821 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-20834 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1702338 Issue Tracking
- https://github.com/advisories/GHSA-j44m-qm6p-hp7m Advisory
- https://github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395d x_refsource_MISC
- https://github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8 x_refsource_MISCPatchThird Party Advisory
- https://github.com/npm/node-tar/commits/v2.2.2 x_refsource_MISC
- https://github.com/npm/node-tar/compare/58a8d43...a5f7779 x_refsource_MISCPatchThird Party Advisory
- https://hackerone.com/reports/344595 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-20834 x_refsource_MISC
- https://www.cve.org/CVERecord?id=CVE-2018-20834
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:1821 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2018-20834 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1702338 | Issue Tracking | |
| https://github.com/advisories/GHSA-j44m-qm6p-hp7m | Advisory | |
| https://github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395d | x_refsource_MISC | |
| https://github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/npm/node-tar/commits/v2.2.2 | x_refsource_MISC | |
| https://github.com/npm/node-tar/compare/58a8d43...a5f7779 | x_refsource_MISCPatchThird Party Advisory | |
| https://hackerone.com/reports/344595 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-20834 | x_refsource_MISC | |
| https://www.cve.org/CVERecord?id=CVE-2018-20834 |
Change history (0)
No recorded changes yet.