VDB
Sign up
LOW3.3

GHSA-f3fg-5j9p-vchc

File exposure in pleaser

Details

pleaser before 0.4.0 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/pleaser
Introduced in: 0Fixed in: 0.4.0

Upgrade pleaser to 0.4.0 or newer (ecosystem crates.io).

References