Time-of-check Time-of-use (TOCTOU) Race Condition in chownr
Low severity
GitHub Reviewed
Published
Feb 10, 2022
to the GitHub Advisory Database
•
Updated Apr 3, 2023
Description
Published by the National Vulnerability Database
Jun 15, 2020
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Apr 3, 2023
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
References