Files
advisory-db/crates/pleaser/RUSTSEC-2021-0104.md
2021-09-10 16:01:55 +00:00

554 B

[advisory]
id = "RUSTSEC-2021-0104"
package = "pleaser"
date = "2021-05-27"
url = "https://nvd.nist.gov/vuln/detail/CVE-2021-31153"
categories = ["file-disclosure"]
cvss = "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
aliases = ["CVE-2021-31153", "GHSA-f3fg-5j9p-vchc"]
[versions]
patched = [">= 0.4"]

File exposure in pleaser

pleaser before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.