Oracle Graalvm 21.2.2 Enterprise Edition

CPE Details

Oracle Graalvm 21.2.2 Enterprise Edition
21.2.2
2022-03-03
19h38 +00:00
2022-05-02
12h57 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:oracle:graalvm:21.2.2:*:*:*:enterprise:*:*:*

Informations

Vendor

oracle

Product

graalvm

Version

21.2.2

Software Edition

enterprise

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-16775 2019-12-12 23h55 +00:00 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
7.7
Haute