Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-32804

33
FAUCET Score

CVE-2021-32804 is an arbitrary file creation/overwrite vulnerability in the npm package "tar" (node-tar) affecting versions prior to 6.1.1, 5.0.6, 4.4.14, and 3.3.2, impacting products like Oracle GraalVM and Siemens Sinec Infrastructure Network Services. This flaw stems from insufficient sanitization of absolute paths with repeated path roots, allowing malicious tar files to write to arbitrary locations. With a CVSS score of 8.1 (High), this vulnerability has a network attack vector, low attack complexity, and can lead to high impact on integrity and availability. While there are no known public exploits or active exploitation (not in KEV or Hot List), it has garnered significant community attention with 4 mentions and 3 media articles, indicating awareness of its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.2CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
>= 4.0.0, < 4.4.14CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
>= 5.0.0, < 5.0.6CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
>= 6.0.0, < 6.1.1CPE matchmatch criteria
cpe:2.3:a:tar_project:tar:*:*:*:*:*:node.js:*:*
20.3.3CPE matchmatch criteria
cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
15.01%
Probability of exploitation in next 30 days
EPSS Percentile
96.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1501 is in the 96th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (43)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: tarFixed in: 6.1.1
npmpatch availablevia ghsa
Product: tarFixed in: 3.2.2
npmpatch availablevia ghsa
Product: tarFixed in: 4.4.14
npmpatch availablevia ghsa
Product: tarFixed in: 5.0.6
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/ocs-must-gather-rhel8:4.9-257.4181add.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/ocs-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/ocs-rhel8-operator:4.9-257.4181add.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-console-rhel8:4.9-39.0f2fa23.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-multicluster-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odf-rhel8-operator:4.9-59.c8bbc1f.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odr-cluster-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odr-hub-operator-bundle:4.9.0-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/odr-rhel8-operator:4.9-27.3d037cc.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/rook-ceph-rhel8-operator:4.9-219.c3f67c6.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/volume-replication-rhel8-operator:4.9-28.82f68db.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs14-nodejs-0:14.17.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs12-nodejs-nodemon-0:2.0.3-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs14-nodejs-0:14.17.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs12-nodejs-0:12.22.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nodejs12-nodejs-nodemon-0:2.0.3-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs12-nodejs-0:12.22.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:12-8040020210817133458.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:14-8040020210817165654.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: nodejs:12-8010020210817113128.c27ad7f8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: nodejs:12-8020020210817125332.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8Fixed in: odf4/cephcsi-rhel8:4.9-164.57484e3.release_4.9
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-header-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/kui-web-terminal-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/mcm-topology-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-prometheus
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/grc-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/search-ui-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-grafana
redhatno patchvia redhat_api
Product: Red Hat Openshift Container Storage 4Fixed in: ocs4/mcg-core-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-grafana

Vendor Advisories (2)

npmGHSA-3jfq-g458-7qm9high

Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization

Aug 3, 2021
redhatCVE-2021-32804Moderate

nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite

Aug 3, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-389290.pdf
PatchThird Party Advisory
github.com / npm/node-tar/commit/1f036ca23f64a547bdd6c79c1a44bc62e8115da4
PatchThird Party Advisory
github.com / npm/node-tar/security/advisories/GHSA-3jfq-g458-7qm9
MitigationThird Party Advisory
npmjs.com / advisories/1770
MitigationThird Party Advisory
npmjs.com / package/tar
ProductThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory