All the vulnerabilities related to the version 1.7.10 of the package
Symlink Arbitrary File Overwrite in bower
Versions of bower
prior to 1.8.8 are affected by an arbitrary file write vulnerability. The vulnerability occurs because bower
does not verify that extracted symbolic links do not resolve to targets outside of the extraction root directory.
Update to version 1.8.8 or later