CVE-2017-18869

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/06/2020
Last modified:
17/06/2020

Description

A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:chownr_project:chownr:*:*:*:*:*:node.js:*:* 1.1.0 (excluding)