CVE-2021-41641

HIGH8.4EPSS 0.13%

Link Following in Deno

發布日:2022/6/13修改日:2023/11/8

描述

Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

參考連結(5)