PT-2019-7501 · Node.Js · Node-Cli

Published

2022-05-24

·

Updated

2022-05-24

·

CVE-2016-1000021

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions node-cli versions 0.1.0 through 0.11.3
Description An issue exists due to predictable temporary file names in lock file and log file, which allows an attacker to overwrite files.
Recommendations For node-cli versions 0.1.0 through 0.11.3, consider updating to a version where this issue is resolved, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the temporary files generated by lock file and log file to minimize the risk of exploitation.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1000021
GHSA-3MRP-QHCJ-MWV5

Affected Products

Node-Cli