A vulnerability described as problematic has been identified in isaacs node-tar up to 7.5.17. This affects an unknown part of the file src/pax.ts of the component PAX Path Handler. Executing a manipulation of the argument path/linkpath can lead to path traversal.
| Vendor | Product | Versions |
|---|---|---|
| isaacs | tar | npm/tar: <= 7.5.17 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| atlassian | bitbucket | cert_advisory | 90% |
| atlassian | fisheye | cert_advisory | 90% |
| atlassian | jira | cert_advisory | 90% |
| atlassian | crucible | cert_advisory | 90% |
| atlassian | bamboo | cert_advisory | 90% |
Updated description with new technical details, changed affected versions to include 7.5.17, updated severity to HIGH, and marked the vulnerability as actively exploited.
Initial creation