First published: Thu Aug 02 2018(Updated: )
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chownr Project Chownr | <1.1.0 | |
redhat/nodejs-chownr | <1.1.0 | 1.1.0 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.