← back
CVE-2019-5484CWE-22

CVE-2019-5484

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.6%
exploitation probability
2.6%top 16% of all CVEs
observed exploitation
nono source reports it
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.
Affected products
n/a · bower