CVE-2016-10538: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
(updated )
The package node-cli
before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
References
Detect and mitigate CVE-2016-10538 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →