CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
80.4%
Updates are now available for v14.x, and v12.x Node.js release lines for the following issues.
There are vulnerabilities in the node-tar which are related to the initial reports and subsequent remediation of node-tar vulnerabilities CVE-2021-32803 and CVE-2021-32804. Subsequent internal security review of node-tar and additional external bounty reports have resulted in the following further CVEs being remediated in node-tar:
Impacts:
Note: CVE-2021-39134 and CVE-2021-39135 previously mentioned in this annoucement do not apply to Node.js 12 and 14 as npm@6 does not depend on the @npm/arborist
module. These vulnerabilities applied to Node.js 16 and have been fixed via the npm 7.21.0 update which was shipped in Node.js v16.8.0 (Current).
The Node.js project will release new versions of 12.x, and 14.x releases lines on or shortly after Tuesday August 31th, 2021 in order to address:
The 14.x release line of Node.js is vulnerable to three high severity issues, and two moderate severity issues
The 12.x release line of Node.js is vulnerable to three high severity issues, and two moderate severity issues.
Releases will be available at, or shortly after, Tuesday, August 31th, 2021.
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
80.4%