2.5
CVSSv3

CVE-2017-18869

Published: 15/06/2020 Updated: 17/06/2020
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 2.5 | Impact Score: 1.4 | Exploitability Score: 1
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A TOCTOU issue in the chownr package prior to 1.1.0 for Node.js 10.10 could allow a local malicious user to trick it into descending into unintended directories via symlink attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

chownr project chownr

Vendor Advisories

Synopsis Moderate: rh-nodejs8-nodejs security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs8-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...