CVE-2019-15119: cnlh nps vulnerable to file overwrite by local user
(updated )
lib/install/install.go
in cnlh nps prior to 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps
, leading to a file overwrite by a local user.
References
Code Behaviors & Features
Detect and mitigate CVE-2019-15119 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →