UNIX symbolic link following in arborist - CVE-2021-39134
Published: March 11, 2022
Vulnerability details
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to a symlink following issue. A local attacker can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
Gentoo Linux
SUSE Linux Enterprise Module for Web Scripting
IBM Security Verify Governance
SINEC INS
nodejs12
nodejs12-debuginfo
nodejs12-debugsource
nodejs12-devel
npm12
nodejs12-docs
nodejs14-docs
npm14
nodejs14-devel
nodejs14-debugsource
nodejs14-debuginfo
nodejs14
How to mitigate CVE-2021-39134
SINEC INS - update to 1.0.1.1
nodejs12 - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-debuginfo - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-debugsource - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-devel - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
npm12 - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-docs - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs14-docs - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
npm14 - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14-devel - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14-debugsource - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14-debuginfo - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14 - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2