#VU23921 UNIX symbolic link following in bin-links
Published: January 3, 2020 / Updated: January 5, 2020
bin-links
isaacs
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a symlink following issue. A remote attacker can create a specially crafted symbolic link to files outside the thenode_modules folder through the bin field. This may allow attackers to access unauthorized files and gain access to sensitive information on the system.