Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0922 | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package. |
Github GHSA |
GHSA-8mfc-v7wv-p62g | Path Traversal in Yarn |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T09:48:25.635Z
Reserved: 2020-01-28T00:00:00
Link: CVE-2020-8131
No data.
Status : Modified
Published: 2020-02-24T15:15:12.020
Modified: 2024-11-21T05:38:21.257
Link: CVE-2020-8131
OpenCVE Enrichment
No data.
EUVD
Github GHSA