CVE-2018-20834 | node-tar up to 4.4.1 Tarball link following (RHSA-2019:1821)
A vulnerability was found in node-tar up to 4.4.1. It has been declared as critical. Impacted is an unknown function of the component Tarball Handler. The manipulation results in link following.
This vulnerability was named CVE-2018-20834. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.