Symlink Arbitrary File Overwrite in bower
High severity
GitHub Reviewed
Published
Sep 17, 2019
to the GitHub Advisory Database
•
Updated Mar 1, 2023
Description
Published by the National Vulnerability Database
Sep 13, 2019
Reviewed
Sep 17, 2019
Published to the GitHub Advisory Database
Sep 17, 2019
Last updated
Mar 1, 2023
Versions of
bower
prior to 1.8.8 are affected by an arbitrary file write vulnerability. The vulnerability occurs becausebower
does not verify that extracted symbolic links do not resolve to targets outside of the extraction root directory.Recommendation
Update to version 1.8.8 or later
References