HIGH7.8
GHSA-pp74-39w2-v4w9
Permissions bypass in pleaser
Details
pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/pleaser
Introduced in:
0Fixed in: 0.4.0Upgrade pleaser to 0.4.0 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31154[ADVISORY]
- https://crates.io/crates/pleaser[WEB]
- https://gitlab.com/edneville/please[WEB]
- https://gitlab.com/edneville/please/-/tree/master/src/bin[WEB]
- https://rustsec.org/advisories/RUSTSEC-2021-0102.html[WEB]
- https://www.openwall.com/lists/oss-security/2021/05/18/1[WEB]