Duplicate Advisory: Node CLI Allows Arbitrary File Overwrite
Low severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 8, 2023
Withdrawn
This advisory was withdrawn on Dec 8, 2023
Description
Published by the National Vulnerability Database
Dec 3, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 28, 2023
Withdrawn
Dec 8, 2023
Last updated
Dec 8, 2023
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-6cpc-mj5c-m9rq. This link is maintained to preserve external references.
Original Description
An issue exists in node-cli 0.1.0 through 0.11.3 due to predictable temporary file names in lock_file and log_file, which allows an attacker to overwrite files.
References