The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/github/hub(Go) | 0 | 1.12.1 | N/A |
| hub(RubyGems) | 0 | 1.12.1 | N/A |
CVSS Metrics