CVE-2021-41641: High severity deno vulnerability
Published Jun 12, 2022
·Updated
Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.
Affected Software
1 affected component
deno deno>=1.10.3<=1.14.0
Event History
Jun 12, 2022
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Deno vulnerability?
The vulnerability ID is CVE-2021-41641.
2
What is the severity of CVE-2021-41641?
The severity of CVE-2021-41641 is high.
3
How does Deno <=1.14.0 file sandbox handle symbolic links incorrectly?
Deno <=1.14.0 file sandbox does not handle symbolic links correctly, allowing the use of the Deno.symlink method to gain access to any directory.
4
Which version of Deno is affected by CVE-2021-41641?
Deno versions between 1.10.3 and 1.14.0 (inclusive) are affected by CVE-2021-41641.
5
How can I fix the CVE-2021-41641 vulnerability?
Update Deno to version 1.14.1 or later to fix the CVE-2021-41641 vulnerability.