CVE-2019-5484
13.09.2019, 18:15
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.
Vendor | Product | Version |
---|---|---|
bower | bower | 𝑥 < 1.8.8 |
𝑥
= Vulnerable software versions
References