Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Masasrono

#30912of 53,634
8.4Total CVSS
Vulnerabilities · 1
PT-2022-11451
8.4
2022-06-12
Deno · Deno · CVE-2021-41641
**Name of the Vulnerable Software and Affected Versions** Deno versions 1.14.0 and earlier **Description** The issue concerns the file sandbox in Deno not handling symbolic links correctly. When Deno is run with specific write access, the `Deno.symlink` method can be exploited to gain access to any directory. **Recommendations** For Deno versions 1.14.0 and earlier, as a temporary workaround, consider disabling the `Deno.symlink` method until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.