PT-2019-17702 · Twitter · Bower

Skyn3T

·

Published

2019-09-13

·

Updated

2023-02-28

·

CVE-2019-5484

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions bower versions prior to 1.8.8
Description The issue allows for a path traversal vulnerability, enabling file write in arbitrary locations via the install command. This occurs because bower does not verify that extracted symbolic links do not resolve to targets outside of the extraction root directory, permitting attackers to write arbitrary files when a malicious package is extracted.
Recommendations Update to version 1.8.8 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2019-5484
GHSA-P6MR-PXG4-68HX

Affected Products

Bower