Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-24T14:41:23

Updated: 2024-08-04T09:48:25.635Z

Reserved: 2020-01-28T00:00:00

Link: CVE-2020-8131

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-02-24T15:15:12.020

Modified: 2020-03-24T14:47:04.697

Link: CVE-2020-8131

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-02-14T00:00:00Z

Links: CVE-2020-8131 - Bugzilla