Gyazo allows local users to write arbitrary files
Moderate severity
GitHub Reviewed
Published
Jan 22, 2018
to the GitHub Advisory Database
•
Updated Sep 5, 2023
Description
Published by the National Vulnerability Database
Jan 10, 2018
Published to the GitHub Advisory Database
Jan 22, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 5, 2023
lib/gyazo/client.rb
in the gyazo gem 1.0.0 for Ruby allows local users to write to arbitrary files via a symlink attack on a temporary file, related to time-based filenames.References