You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Arbitrary File Write vulnerability found in bin-links before 1.1.5. The package fails to restrict access to folders outside of the intended node_modules folder through the bin field. This allows attackers to create arbitrary files in the system.
WS-2019-0337 - Medium Severity Vulnerability
Vulnerable Library - bin-links-1.1.2.tgz
JavaScript package binary linker
Library home page: https://registry.npmjs.org/bin-links/-/bin-links-1.1.2.tgz
Path to dependency file: sync-stripe-to-zendesk/package.json
Path to vulnerable library: sync-stripe-to-zendesk/node_modules/npm/node_modules/bin-links/package.json
Dependency Hierarchy:
Found in HEAD commit: 30480e820ede5e69748f350c3f0e86fa42e434f8
Vulnerability Details
Arbitrary File Write vulnerability found in bin-links before 1.1.5. The package fails to restrict access to folders outside of the intended node_modules folder through the bin field. This allows attackers to create arbitrary files in the system.
Publish Date: 2019-12-11
URL: WS-2019-0337
CVSS 2 Score Details (5.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: npm/bin-links@642cd18
Release Date: 2019-12-17
Fix Resolution: bin-links - 1.1.5
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: