Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-32803

29
FAUCET Score

CVE-2021-32803 is an arbitrary file creation/overwrite vulnerability in the npm package "tar" (node-tar), affecting versions prior to 6.1.2, 5.0.7, 4.4.15, and 3.2.3, as well as various Oracle and Siemens products utilizing this package. The vulnerability, rated 8.1 HIGH, allows an attacker to bypass symlink protection by first creating a directory and then replacing it with a symlink, enabling arbitrary file creation and overwrite. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered community discussion and media coverage, indicating awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.3CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
>= 4.0.0, < 4.4.15CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
>= 5.0.0, < 5.0.7CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
>= 6.0.0, < 6.1.2CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
20.3.3CPE matchmatch criteria
cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.80%
Probability of exploitation in next 30 days
EPSS Percentile
94.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0780 is in the 94th percentile among its peer group of 14,855 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (42)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: tarFixed in: 3.2.3
npmpatch availablevia ghsa
Product: tarFixed in: 4.4.15
npmpatch availablevia ghsa
Product: tarFixed in: 5.0.7
npmpatch availablevia ghsa
Product: tarFixed in: 6.1.2
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/ocs-must-gather-rhel8:4.9-257.4181add.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/ocs-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/ocs-rhel8-operator:4.9-257.4181add.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-console-rhel8:4.9-39.0f2fa23.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-multicluster-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-rhel8-operator:4.9-59.c8bbc1f.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odr-cluster-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odr-hub-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odr-rhel8-operator:4.9-27.3d037cc.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/rook-ceph-rhel8-operator:4.9-219.c3f67c6.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/volume-replication-rhel8-operator:4.9-28.82f68db.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs14-nodejs-0:14.17.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs12-nodejs-nodemon-0:2.0.3-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs14-nodejs-0:14.17.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs12-nodejs-0:12.22.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs12-nodejs-nodemon-0:2.0.3-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs12-nodejs-0:12.22.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:12-8040020210817133458.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:14-8040020210817165654.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: nodejs:12-8010020210817113128.c27ad7f8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: nodejs:12-8020020210817125332.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/cephcsi-rhel8:4.9-164.57484e3.release_4.9
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/kui-web-terminal-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/mcm-topology-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-ui-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-header-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-grafana
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/grc-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/search-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Openshift Container Storage 4Fixed in: ocs4/mcg-core-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-grafana

Vendor Advisories (2)

npmGHSA-r628-mhmh-qjhwhigh

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

Aug 3, 2021
redhatCVE-2021-32803Moderate

nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite

Aug 3, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-389290.pdf
PatchThird Party Advisory
github.com / npm/node-tar/commit/9dbdeb6df8e9dbd96fa9e84341b9d74734be6c20
PatchThird Party Advisory
github.com / npm/node-tar/security/advisories/GHSA-r628-mhmh-qjhw
MitigationThird Party Advisory
npmjs.com / advisories/1771
MitigationThird Party Advisory
npmjs.com / package/tar
ProductThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory