A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
https://github.com/isaacs/chownr/issues/14
https://bugzilla.redhat.com/show_bug.cgi?id=1611614
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863985
Source: Mitre, NVD
Published: 2020-06-15
Updated: 2020-06-17
Base Score: 1.9
Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:P/A:N
Severity: Low
Base Score: 2.5
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N