The package node-cli before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
Loading...
Loading...
The package node-cli before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
May 31, 2018
November 21, 2024
See which npm, PyPI, Go, and Maven packages are affected by CVE-2016-10538
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.