mirror of
https://github.com/OMGeeky/advisory-db.git
synced 2026-01-09 13:09:27 +01:00
Add rustsec advisory for GHSA-pp74-39w2-v4w9 (#1016)
This commit is contained in:
16
crates/pleaser/RUSTSEC-0000-0000.md
Normal file
16
crates/pleaser/RUSTSEC-0000-0000.md
Normal file
@@ -0,0 +1,16 @@
|
||||
```toml
|
||||
[advisory]
|
||||
id = "RUSTSEC-0000-0000"
|
||||
package = "pleaser"
|
||||
date = "2021-05-27"
|
||||
url = "https://nvd.nist.gov/vuln/detail/CVE-2021-31154"
|
||||
categories = ["privilege-escalation"]
|
||||
cvss = "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
aliases = ["CVE-2021-31154"]
|
||||
[versions]
|
||||
patched = [">= 0.4"]
|
||||
```
|
||||
|
||||
# Permissions bypass in pleaser
|
||||
|
||||
pleaseedit in pleaser before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
|
||||
Reference in New Issue
Block a user