What the vulnerability does

01Description

Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.

Key dates

02Disclosure timeline

September 13, 2019 CVE published
August 4, 2024 Record updated