Node.js 的 包用于解压归档文件。在 10.2.2 和 11.1.4 版本之前,默认的 API 依赖于词法包含检查(lexical containment checks),但这些检查未能考虑到内核可能跟随攻击者植入的符号链接链(symlink chain)。攻击者可以提供一个精心构造的包含串联符号链接条目的归档文件,使得后续的条目解析到输出目录之外。这导致攻击者可以读取或写入输出目录之外的文件;通过覆盖启动脚本或配置文件,可能引发远程代码执行。 维护中的 包已在版本 10.2.2 和 11.1.4 中修复该问
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kevva | decompress | <= 4.2.1 |
affected |
| XhmikosR | decompress | < 10.2.2 |
affected |
>= 11.0.0, < 11.1.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| XhmikosR | decompress | < 10.2.2 | - |
|
| kevva | decompress | <= 4.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet