QID 983395
QID 983395: Nodejs (npm) Security Update for bower (GHSA-p6mr-pxg4-68hx)
Versions of `bower` prior to 1.8.8 are affected by an arbitrary file write vulnerability. The vulnerability occurs because `bower` does not verify that extracted symbolic links do not resolve to targets outside of the extraction root directory.
## Recommendation
Update to version 1.8.8 or later
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p6mr-pxg4-68hx for updates pertaining to this vulnerability.
Vendor References
- GHSA-p6mr-pxg4-68hx -
github.com/advisories/GHSA-p6mr-pxg4-68hx
CVEs related to QID 983395
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p6mr-pxg4-68hx | bower |
|