2.3.1
4 years ago
2 days ago
Known vulnerabilities in the @tinacms/graphql package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@tinacms/graphql is a GraphQL database generating component for Tina, the headless content management system with support for Markdown, MDX, JSON, YAML, and more. Affected versions of this package are vulnerable to Symlink Attack in the FilesystemBridge How to fix Symlink Attack? Upgrade | <2.2.2 |
@tinacms/graphql is a GraphQL database generating component for Tina, the headless content management system with support for Markdown, MDX, JSON, YAML, and more. Affected versions of this package are vulnerable to Symlink Attack in the handling of media endpoints when symlinks or junctions exist within the media directory. An attacker can access, list, write, or delete files outside the intended media root by supplying crafted paths that traverse through existing links. How to fix Symlink Attack? Upgrade | <2.2.2 |
@tinacms/graphql is a GraphQL database generating component for Tina, the headless content management system with support for Markdown, MDX, JSON, YAML, and more. Affected versions of this package are vulnerable to Directory Traversal due to improper validation of backslashes on non-Windows platforms (Mac/Linux) in How to fix Directory Traversal? Upgrade | <2.2.2 |