CVE-2021-23484

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
28/01/2022
Last modified:
08/08/2023

Description

The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zip-local_project:zip-local:*:*:*:*:*:node.js:*:* 0.3.5 (excluding)