GHSA-3mrp-qhcj-mwv5
Dashboard / Vulnerabilities / GHSA-3mrp-qhcj-mwv5
Summary: Duplicate Advisory: Node CLI Allows Arbitrary File Overwrite
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6cpc-mj5c-m9rq. This link is maintained to preserve external references. ## Original Description An issue exists in node-cli 0.1.0 through 0.11.3 due to predictable temporary file names in lock_file and log_file, which allows an attacker to overwrite files.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-1000021, https://nvd.nist.gov/vuln/detail/CVE-2016-10538, https://github.com/node-js-libs/cli/issues/81, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000021, https://web.archive.org/web/20190430172230/https://www.npmjs.com/advisories/95
Affected packages
Package
Name: cli
Purl: pkg:npm/cli
Affected ranges
Type: SEMVER
Events:
