sharkdp BAT before 0.18.2 executes less.exe from the current working directory.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://github.com/sharkdp/bat/releases/tag/v0.18.2 | third party advisory release notes |
https://github.com/sharkdp/bat/pull/1724 | third party advisory patch |
https://github.com/sharkdp/bat/commit/bf2b2df9c9e218e35e5a38ce3d03cffb7c363956 | third party advisory patch |
https://vuln.ryotak.me/advisories/53 | third party advisory |