GHSA-67hm-27mx-9cg7

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-67hm-27mx-9cg7/GHSA-67hm-27mx-9cg7.json
Aliases
  • CVE-2021-41641
Published
2022-06-13T00:00:19Z
Modified
2022-06-23T06:44:34Z
Details

Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

References

Affected packages

crates.io / deno

deno

Affected ranges

Type
SEMVER
Events
Introduced
0
Fixed
1.16.0

Affected versions