Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18869

Опубликовано: 31 июл. 2018
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4nodejs-chownrWill not fix
Red Hat Software Collectionsrh-nodejs6-nodejs-chownrWill not fix
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs8-nodejsFixedRHSA-2020:262519.06.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-nodejs8-nodejsFixedRHSA-2020:262519.06.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-nodejs8-nodejsFixedRHSA-2020:262519.06.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=1611613nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js

EPSS

Процентиль: 25%
0.00334
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
около 6 лет назад

A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.

CVSS3: 2.5
nvd
около 6 лет назад

A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.

CVSS3: 2.5
debian
около 6 лет назад

A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 co ...

CVSS3: 2.5
github
больше 4 лет назад

Time-of-check Time-of-use (TOCTOU) Race Condition in chownr

CVSS3: 2.5
fstec
около 9 лет назад

Уязвимость пакета chownr программной платформы Node.js, позволяющая нарушителю получить несанкционированный доступ к произвольным каталогам

EPSS

Процентиль: 25%
0.00334
Низкий

7.7 High

CVSS3