eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.
| Software | From | Fixed in |
|---|---|---|
| eroaster / eroaster | 2.0.0 | 2.0.0.x |
| eroaster / eroaster | 2.2.0 | 2.2.0.x |
| eroaster / eroaster | 2.1.0 | 2.1.0.x |