CVE-2017-18869
ADVISORY - githubSummary
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
EPSS Score: 0.00123 (0.325)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Time-of-check Time-of-use (TOCTOU) Race Condition
ADVISORY - github
Time-of-check Time-of-use (TOCTOU) Race Condition
ADVISORY - gitlab
ADVISORY - redhat
Time-of-check Time-of-use (TOCTOU) Race Condition
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in