A vulnerability, which was classified as critical, has been found in node-tar up to 3.2.2/4.4.14/5.0.6/6.1.1 on npm (NPM Package). Affected by this issue is an unknown functionality of the component Symbolic Links Handler. Upgrading to version 3.2.3, 4.4.15, 5.0.7 or 6.1.2 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.
node-tar up to 3.2.2/4.4.14/5.0.6/6.1.1 on npm Symbolic Links path traversal
Description A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2,
Description The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542
CVE-2023-46589 : APACHE TOMCAT UP TO 8.5.95/9.0.82/10.1.15/11.0.0-M10 HTTP TRAILER HEADER REQUEST SMUGGLING
Description Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82