|
|
|
|
|
by jshmrsn
61 days ago
|
|
Am I missing something, or do this article’s purported vulnerabilities rely on an assumption that an attacker already has enough access to your system that the attacker can modify files which your code is referencing by path? Isn’t this more of an escalation vector than a vulnerability in itself? I’m trying to understand the practical takeaway. |
|
e.g. in an installer:
I'm collapsing and simplifying - lots more possibilities and detail than the above.