uu_rm is vulnerable to Protection Mechanism Bypass
66
Medium Risk
rm accepts abbreviated spellings of --no-preserve-root, such as --n or --no, that GNU rm rejects. Passing those abbreviations disables the guard that refuses recursive operation on /. A user or script that passes such an option while running rm -r can delete the entire root filesystem. The fix rejects these abbreviations so only the full --no-preserve-root flag disables the guard.
You are affected if you are using a version that falls within the vulnerable range and you run rm recursively while passing an abbreviated form of the --no-preserve-root flag.
uu_rm is vulnerable to Protection Mechanism Bypass in versions 0.0.1 - 0.5.0.
Upgrade the uu_rm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.