PT-2021-21258 · Unknown+1 · Dandavison Delta+1
Ryotak
·
Published
2021-07-12
·
Updated
2024-06-15
·
CVE-2021-36376
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dandavison delta version 0.8.2 and earlier
git-delta version 0.8.2 and earlier
Description
The issue arises when the software resolves an executable's pathname as a relative path from the current directory on Windows. This could potentially lead to security issues.
Recommendations
For dandavison delta version 0.8.2 and earlier, update to version 0.8.3 or later to resolve the issue.
For git-delta version 0.8.2 and earlier, update to version 0.8.3 or later to resolve the issue.
Fix
Relative Path Traversal
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dandavison Delta
Git-Delta