The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Hub |
Github |
* |
1.12.0 (including) |
References