VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 54 of 83
  • CVE-2020-3835MedFeb 27, 2020
    risk 0.29cvss 4.4epss 0.00

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.3. A malicious application may be able to access restricted files.

  • CVE-2014-1938MedNov 21, 2019
    risk 0.29cvss 5.5epss 0.00

    python-rply before 0.7.4 insecurely creates temporary files.

  • CVE-2019-18466MedOct 28, 2019
    risk 0.29cvss 5.5epss 0.01

    An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that,…

  • CVE-2019-11230MedJul 18, 2019
    risk 0.29cvss 4.4epss 0.01

    In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be…

  • CVE-2018-1063MedMar 2, 2018
    risk 0.29cvss 4.4epss 0.00

    Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when…

  • CVE-2017-15111MedJan 20, 2018
    risk 0.29cvss 5.5epss 0.00

    keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.

  • CVE-2014-1859MedJan 8, 2018
    risk 0.29cvss 5.5epss 0.00

    (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.

  • CVE-2014-4978MedDec 29, 2017
    risk 0.29cvss 5.5epss 0.00

    The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.

  • CVE-2015-3156MedAug 11, 2017
    risk 0.29cvss 5.5epss 0.00

    The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service/config.py, write_config function in trove/guestagent/datastore/experimental/redis/service.py,…

  • CVE-2015-8326MedJun 7, 2017
    risk 0.29cvss 5.5epss 0.00

    The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.

  • CVE-2024-52522MedNov 15, 2024
    risk 0.28cvss epss 0.00

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions…

  • CVE-2024-9341MedOct 1, 2024
    risk 0.28cvss 5.4epss 0.01

    A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting…

  • CVE-2023-28871MedDec 9, 2023
    risk 0.28cvss 4.3epss 0.01

    Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.

  • CVE-2022-38482MedJan 10, 2023
    risk 0.28cvss 4.3epss 0.01

    A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.

  • CVE-2022-4122MedDec 8, 2022
    risk 0.28cvss 5.3epss 0.01

    A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

  • CVE-2021-44141MedFeb 21, 2022
    risk 0.28cvss 4.3epss 0.01

    All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for…

  • CVE-2020-4966MedJan 21, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The…

  • CVE-2026-58203MedJul 6, 2026
    risk 0.27cvss 5.3epss 0.00

    pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry inside secrets_dir that is a symbolic link pointing…

  • CVE-2026-55686MedJun 26, 2026
    risk 0.27cvss 5.3epss 0.00

    Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that…

  • CVE-2026-39819MedMay 7, 2026
    risk 0.27cvss 5.3epss 0.00

    The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.