Description
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0240 | The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to. |
Github GHSA |
GHSA-6cpc-mj5c-m9rq | Arbitrary File Write in cli |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T01:36:47.221Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2016-10538
No data.
Status : Modified
Published: 2018-05-31T20:29:01.363
Modified: 2024-11-21T02:44:13.547
Link: CVE-2016-10538
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA