Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
{ "availability": "No subscription required", "binaries": [ { "binary_name": "golang-github-syncthing-syncthing-dev", "binary_version": "0.14.43+ds1-6" }, { "binary_name": "syncthing", "binary_version": "0.14.43+ds1-6" }, { "binary_name": "syncthing-dbgsym", "binary_version": "0.14.43+ds1-6" }, { "binary_name": "syncthing-discosrv", "binary_version": "0.14.43+ds1-6" }, { "binary_name": "syncthing-discosrv-dbgsym", "binary_version": "0.14.43+ds1-6" }, { "binary_name": "syncthing-relaysrv", "binary_version": "0.14.43+ds1-6" }, { "binary_name": "syncthing-relaysrv-dbgsym", "binary_version": "0.14.43+ds1-6" } ] }