CVE-2017-18869
ADVISORY - githubSummary
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
EPSS Score: 0.00123 (0.325)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Time-of-check Time-of-use (TOCTOU) Race Condition
ADVISORY - github
Time-of-check Time-of-use (TOCTOU) Race Condition
ADVISORY - gitlab
ADVISORY - redhat
Time-of-check Time-of-use (TOCTOU) Race Condition
NIST
CREATED
UPDATED
ADVISORY IDCVE-2017-18869
EXPLOITABILITY SCORE
1
EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
2.5lowGitHub
CREATED
UPDATED
ADVISORY IDGHSA-c6rq-rjc2-86v2
EXPLOITABILITY SCORE
1.0
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
2.5lowDebian
CREATED
UPDATED
ADVISORY IDCVE-2017-18869
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2017-18869
EXPLOITABILITY SCORE
1.0
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
2.5mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2017-18869
EXPLOITABILITY SCORE
2.5
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.7mediumintheWild
CREATED
UPDATED
ADVISORY IDCVE-2017-18869
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-