You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
adm-zip versions before 0.4.9 are vulnerable to Arbitrary File Write due to extraction of a specifically crafted archive that contains path traversal filenames
WS-2019-0231 - Medium Severity Vulnerability
Vulnerable Libraries - adm-zip-0.4.7.tgz, adm-zip-0.4.4.tgz
adm-zip-0.4.7.tgz
A Javascript implementation of zip for nodejs. Allows user to create or extract zip files both in memory or to/from disk
Library home page: https://registry.npmjs.org/adm-zip/-/adm-zip-0.4.7.tgz
Path to dependency file: /tmp/ws-scm/angular-shopping/package.json
Path to vulnerable library: /tmp/ws-scm/angular-shopping/node_modules/adm-zip/package.json
Dependency Hierarchy:
adm-zip-0.4.4.tgz
A Javascript implementation of zip for nodejs. Allows user to create or extract zip files both in memory or to/from disk
Library home page: https://registry.npmjs.org/adm-zip/-/adm-zip-0.4.4.tgz
Path to dependency file: /tmp/ws-scm/angular-shopping/package.json
Path to vulnerable library: /tmp/ws-scm/angular-shopping/node_modules/webdriver-js-extender/node_modules/adm-zip/package.json
Dependency Hierarchy:
Found in HEAD commit: d9a0e4f22259cd9938eb227e325db4e5e32f57a7
Vulnerability Details
adm-zip versions before 0.4.9 are vulnerable to Arbitrary File Write due to extraction of a specifically crafted archive that contains path traversal filenames
Publish Date: 2019-09-09
URL: WS-2019-0231
CVSS 2 Score Details (5.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/994
Release Date: 2019-09-09
Fix Resolution: 0.4.9
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: