CVE-2018-20834
Estado: ModificadaAlta (7.5)—
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.15%
- Percentil entre todas las CVEs puntuadas: 88
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-59
Referencias
- https://access.redhat.com/errata/RHSA-2019:1821
- https://github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395d
- https://github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8
- https://github.com/npm/node-tar/commits/v2.2.2
- https://github.com/npm/node-tar/compare/58a8d43...a5f7779
- https://hackerone.com/reports/344595
- https://nvd.nist.gov/vuln/detail/CVE-2018-20834
- https://access.redhat.com/errata/RHSA-2019:1821
- https://github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395d
- https://github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8
- https://github.com/npm/node-tar/commits/v2.2.2
- https://github.com/npm/node-tar/compare/58a8d43...a5f7779
- https://hackerone.com/reports/344595
- https://nvd.nist.gov/vuln/detail/CVE-2018-20834
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-20834",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-04-30T19:29:03.327",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2019:1821",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395d",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/node-tar/commits/v2.2.2",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/npm/node-tar/compare/58a8d43...a5f7779",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://hackerone.com/reports/344595",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20834",
"source": "cve@mitre.org"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1821",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395d",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/node-tar/commits/v2.2.2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/npm/node-tar/compare/58a8d43...a5f7779",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/344595",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20834",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2)."
},
{
"lang": "es",
"value": "Se detecto una vulnerabilidad en node-tar en versiones anteriores a la 4.4.2 (excluyendo la versión 2.2.2). Existe un problema de sobrescritura arbitraria de archivos cuando se extrae un tarball que contiene un enlace físico a un archivo que ya existe en el sistema, junto con un archivo plano posterior con el mismo nombre que el enlace físico. Este contenido de archivo simple reemplaza el contenido de archivo existente. Se ha aplicado un parche a node-tar v2.2.2)."
}
],
"lastModified": "2026-06-17T01:53:33.490",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:isaacs:tar:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D32C411B-93FB-4DCD-BAB8-4D3C56736A82",
"versionEndExcluding": "2.2.2"
},
{
"criteria": "cpe:2.3:a:isaacs:tar:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7DA25DE4-D41D-4253-9C18-A15793E0B07D",
"versionEndExcluding": "4.4.2",
"versionStartIncluding": "3.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}