Arbitrary File Overwrite in decompress-zip
High severity
GitHub Reviewed
Published
Sep 2, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 0.2.2
>= 0.3.0, < 0.3.2
Patched versions
0.2.2
0.3.2
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 2, 2020
Last updated
Jan 9, 2023
Vulnerable versions of
decompress-zip
are affected by the Zip-Slip vulnerability, an arbitrary file write vulnerability. The vulnerability occurs becausedecompress-zip
does not verify that extracted files do not resolve to targets outside of the extraction root directory.Recommendation
For
decompress-zip
0.2.x upgrade to 0.2.2 or later.For
decompress-zip
0.3.x upgrade to 0.3.2 or later.References