A vulnerability classified as problematic has been found in isaacs node-tar up to 7.5.18. This vulnerability affects unknown code of the file src/extract.ts of the component Decompression. The manipulation leads to memory corruption. The attack is possible to be carried out remotely.
| Vendor | Product | Versions |
|---|---|---|
| isaacs | tar | npm/tar: <= 7.5.18 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| atlassian | bamboo | cert_advisory | 90% |
| atlassian | crucible | cert_advisory | 90% |
| atlassian | bitbucket | cert_advisory | 90% |
| atlassian | fisheye | cert_advisory | 90% |
| atlassian | confluence | cert_advisory | 90% |
Updated description with details on memory corruption, changed severity to HIGH, and noted that the vulnerability is actively exploited.
Initial creation