This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: A Path Traversal vulnerability in `node-tar` (npm package). ๐ฆ **Consequences**: Due to insufficient absolute path cleaning, attackers can create or overwrite arbitrary files on the system.โฆ
๐ก๏ธ **Root Cause**: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). ๐ **Flaw**: The library fails to properly sanitize absolute paths during extraction, allowing directory traversal attacks.
Q3Who is affected? (Versions/Components)
๐ฅ **Affected**: Users of the `node-tar` npm package. ๐ **Vendor**: npm. โ ๏ธ **Note**: Since `npm` itself uses `node-tar`, the npm tool is also indirectly affected by this vulnerability.
Q4What can hackers do? (Privileges/Data)
๐ต๏ธ **Hackers Can**: Create arbitrary files or overwrite existing ones. ๐ **Privileges**: Local access required, but can lead to system compromise.โฆ
๐ **Threshold**: Low to Medium. ๐ฑ๏ธ **Requirements**: Local Access (AV:L), Low Complexity (AC:L), No Privileges Required (PR:N), but User Interaction (UI:R) is needed (e.g., clicking a malicious link or running a command)โฆ
๐ฅ **Public Exploit**: YES. ๐ **PoC Available**: A GitHub repository (`yamory/CVE-2021-32804`) provides Docker-based reproduction steps. ๐ป **Proof**: Demonstrates overwriting `.bashrc` to execute commands upon `su node`.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Scan for `node-tar` versions in your `package-lock.json` or `node_modules`. ๐ ๏ธ **Feature**: Check if your app extracts tarballs from untrusted sources.โฆ
โ **Fixed**: YES. ๐ **Patch**: Official commit `1f036ca23f64a547bdd6c79c1a44bc62e8115da4` on GitHub addresses the issue. ๐ **Action**: Update `node-tar` to the patched version immediately.
Q9What if no patch? (Workaround)
๐ง **No Patch?**: Avoid extracting untrusted tar files. ๐ **Mitigation**: Implement strict path validation before extraction.โฆ
๐จ **Urgency**: HIGH. ๐ด **Priority**: Critical for Node.js developers. โณ **Reason**: CVSS Score indicates High impact (C:H, I:H). Since npm is widely used, the attack surface is broad. Patch ASAP!