Lucene search

K
cvelistMitreCVELIST:CVE-2020-12265
HistoryApr 26, 2020 - 4:46 p.m.

CVE-2020-12265

2020-04-2616:46:21
mitre
www.cve.org
7

AI Score

9.5

Confidence

High

EPSS

0.006

Percentile

78.9%

The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via …/ in an archive member, when a symlink is used, because of Directory Traversal.

AI Score

9.5

Confidence

High

EPSS

0.006

Percentile

78.9%