{"id":"GHSA-67hm-27mx-9cg7","summary":"Link Following in Deno","details":"Deno \u003c=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.","aliases":["CVE-2021-41641"],"modified":"2023-11-08T04:07:00.645155Z","published":"2022-06-13T00:00:19Z","database_specific":{"github_reviewed_at":"2022-06-23T06:44:34Z","nvd_published_at":"2022-06-12T13:15:00Z","cwe_ids":["CWE-59"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41641"},{"type":"WEB","url":"https://github.com/denoland/deno/issues/12152"},{"type":"WEB","url":"https://github.com/denoland/deno/pull/12554"},{"type":"WEB","url":"https://github.com/denoland/deno/commit/d44011a69e0674acfa9c59bd7ad7f0523eb61d42"},{"type":"WEB","url":"https://hackers.report/report/614876917a7b150012836bb8"}],"affected":[{"package":{"name":"deno","ecosystem":"crates.io","purl":"pkg:cargo/deno"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.16.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-67hm-27mx-9cg7/GHSA-67hm-27mx-9cg7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}