Lucene search

K
osvGoogleOSV:GHSA-PP74-39W2-V4W9
HistoryAug 25, 2021 - 9:01 p.m.

Permissions bypass in pleaser

2021-08-2521:01:44
Google
osv.dev
8
permissions bypass
pleaser software
symlink attack

EPSS

0

Percentile

5.1%

pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.