From 951070000d3f5b4e0ae3f8bd92de7bae17e0d907 Mon Sep 17 00:00:00 2001 From: Jon Moroney Date: Thu, 9 Sep 2021 14:49:39 -0700 Subject: [PATCH] Add rustsec advisory for GHSA-f3fg-5j9p-vchc (#1020) --- crates/pleaser/RUSTSEC-0000-0000.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 crates/pleaser/RUSTSEC-0000-0000.md diff --git a/crates/pleaser/RUSTSEC-0000-0000.md b/crates/pleaser/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..122377e --- /dev/null +++ b/crates/pleaser/RUSTSEC-0000-0000.md @@ -0,0 +1,16 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "pleaser" +date = "2021-05-27" +url = "https://nvd.nist.gov/vuln/detail/CVE-2021-31153" +categories = ["file-disclosure"] +cvss = "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" +aliases = ["CVE-2021-31153"] +[versions] +patched = [">= 0.4"] +``` + +# File exposure in pleaser + +pleaser before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.