Lucene search

K
nodejsSnyk security teamNODEJS:681
HistoryAug 03, 2018 - 3:15 p.m.

Arbitrary File Write via Archive Extraction

2018-08-0315:15:42
snyk security team
www.npmjs.com
598

0.001 Low

EPSS

Percentile

47.6%

Overview

Versions of adm-zip before 0.4.9 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (../../file.txt for example).

Recommendation

Update to version 0.4.9 or later.

References

CPENameOperatorVersion
adm-ziplt0.4.9