Описание
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
Ссылки
- Third Party Advisory
- Permissions Required
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Permissions Required
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
EPSS
2.5 Low
CVSS3
1.9 Low
CVSS2
Дефекты
Связанные уязвимости
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 co ...
Time-of-check Time-of-use (TOCTOU) Race Condition in chownr
Уязвимость пакета chownr программной платформы Node.js, позволяющая нарушителю получить несанкционированный доступ к произвольным каталогам
EPSS
2.5 Low
CVSS3
1.9 Low
CVSS2