Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
{
"binaries": [
{
"binary_name": "golang-github-syncthing-syncthing-dev",
"binary_version": "0.14.43+ds1-6"
},
{
"binary_name": "syncthing",
"binary_version": "0.14.43+ds1-6"
},
{
"binary_name": "syncthing-dbgsym",
"binary_version": "0.14.43+ds1-6"
},
{
"binary_name": "syncthing-discosrv",
"binary_version": "0.14.43+ds1-6"
},
{
"binary_name": "syncthing-discosrv-dbgsym",
"binary_version": "0.14.43+ds1-6"
},
{
"binary_name": "syncthing-relaysrv",
"binary_version": "0.14.43+ds1-6"
},
{
"binary_name": "syncthing-relaysrv-dbgsym",
"binary_version": "0.14.43+ds1-6"
}
],
"availability": "No subscription required"
}