LOW3.3
GHSA-f3fg-5j9p-vchc
File exposure in pleaser
Details
pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/pleaser
Introduced in:
0Fixed in: 0.4.0Upgrade pleaser to 0.4.0 or newer (ecosystem crates.io).