CVE-2019-5484
13.09.2019, 18:15
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.
| Vendor | Product | Version |
|---|---|---|
| bower | bower | 𝑥 < 1.8.8 |
𝑥
= Vulnerable software versions
References