Junglewise Threat Intelligence

CVE-2021-37712: npm tar arbitrary file creation via directory cache poisoning

CVE-2021-37712 · Severity: low · CVSS 3.1 · Published 2021-08-31

Vendors: npm.

Executive brief

npm's tar package is used to extract compressed tar archives in Node.js applications. A flaw in its symlink protection allows a specially crafted tar file to bypass security checks and create or overwrite arbitrary files on the system. An attacker can exploit this by providing a malicious tar archive, potentially leading to code execution or data compromise.

Technical details

The vulnerability is a path traversal issue (CWE-22, CWE-59) in the directory cache and path reservation logic of node-tar. The root cause is insufficient normalization when caching directory paths: the library failed to normalize unicode characters and Windows 8.3 short paths correctly. An attacker can craft a tar archive containing two directories with names that normalize to the same path (via unicode normalization or 8.3 short names), followed by a symlink using the first form and a file using the second form. This poisons the directory cache, causing the symlink check to be bypassed and allowing extraction to an arbitrary location. No authentication is required; exploitation occurs during tar extraction of untrusted archives. The vulnerability has been fixed in versions 4.4.18, 5.0.10, and 6.1.9 via proper unicode normalization using String.normalize('NFKD') and clearing the directory cache when symlinks are encountered on Windows.

Affected products

  • npm tar 3.0.0 through 4.4.17, 5.0.0 through 5.0.9, 6.0.0 through 6.1.8

Timeline

  • 2021-08-31: disclosed
  • 2021-08-31: patched: versions 4.4.18, 5.0.10, 6.1.9 released

References