Filtered by vendor Chownr Project
Subscribe
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-18869 | 1 Chownr Project | 1 Chownr | 2020-06-17 | 1.9 LOW | 2.5 LOW |
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks. |