cve/2024/CVE-2024-27931.md
2024-06-08 09:32:58 +00:00

974 B

CVE-2024-27931

Description

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in Deno.makeTemp* APIs would allow for creation of files outside of the allowed directories. This may allow the user to overwrite important files on the system that may affect other systems. A user may provide a prefix or suffix to a Deno.makeTemp* API containing path traversal characters. This is fixed in Deno 1.41.1.

POC

Reference

No PoCs from references.

Github