HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability
Low severity
GitHub Reviewed
Published
Oct 28, 2023
to the GitHub Advisory Database
•
Updated Nov 14, 2023
Description
Published by the National Vulnerability Database
Oct 27, 2023
Published to the GitHub Advisory Database
Oct 28, 2023
Reviewed
Oct 31, 2023
Last updated
Nov 14, 2023
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
References