Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.
References
Link Resource
https://github.com/denoland/deno/issues/12152 Exploit Issue Tracking Third Party Advisory
https://hackers.report/report/614876917a7b150012836bb8 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-12T12:12:08

Updated: 2022-06-12T12:12:08

Reserved: 2021-09-27T00:00:00


Link: CVE-2021-41641

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-12T13:15:07.747

Modified: 2022-06-21T14:47:44.067


Link: CVE-2021-41641

JSON object: View

cve-icon Redhat Information

No data.

CWE