PT-2019-7501 · Node.Js · Node-Cli

Publicado

2022-05-24

·

Atualizado

2022-05-24

·

CVE-2016-1000021

CVSS v3.1

3.5

Baixa

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions node-cli versions 0.1.0 through 0.11.3
Description An issue exists due to predictable temporary file names in lock file and log file, which allows an attacker to overwrite files.
Recommendations For node-cli versions 0.1.0 through 0.11.3, consider updating to a version where this issue is resolved, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the temporary files generated by lock file and log file to minimize the risk of exploitation.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-1000021
GHSA-3MRP-QHCJ-MWV5

Produtos afetados

Node-Cli