Description
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0956 | A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks. |
Github GHSA |
GHSA-c6rq-rjc2-86v2 | Time-of-check Time-of-use (TOCTOU) Race Condition in chownr |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:37:44.315Z
Reserved: 2020-06-15T00:00:00.000Z
Link: CVE-2017-18869
No data.
Status : Modified
Published: 2020-06-15T15:15:09.317
Modified: 2024-11-21T03:21:08.307
Link: CVE-2017-18869
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA