原始 OSV JSON{
"id": "GHSA-wxj7-97fp-j53j",
"aliases": [
"CVE-2021-23484"
],
"details": "The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.",
"summary": "Exposure of Resource to Wrong Sphere in Zip-Local",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.3.5"
}
]
}
],
"package": {
"name": "zip-local",
"ecosystem": "npm"
}
}
],
"modified": "2022-02-07T21:20:28Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"published": "2022-02-01T00:46:01Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-23484",
"type": "ADVISORY"
},
{
"url": "https://github.com/Mostafa-Samir/zip-local/commit/6bb9b59733df379ac168aa705790bd8339b4bf9b",
"type": "WEB"
},
{
"url": "https://github.com/Mostafa-Samir/zip-local/commit/949446a95a660c0752b1db0c654f0fd619ae6085",
"type": "WEB"
},
{
"url": "https://github.com/Mostafa-Samir/zip-local",
"type": "PACKAGE"
},
{
"url": "https://github.com/Mostafa-Samir/zip-local/blob/master/main.js%23L365",
"type": "WEB"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-ZIPLOCAL-2327477",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-29",
"CWE-668"
],
"severity": "CRITICAL",
"github_reviewed": true,
"nvd_published_at": "2022-01-28T22:15:00Z",
"github_reviewed_at": "2022-01-31T19:55:36Z"
}
}