An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: fedora
Published: 2024-02-04T19:16:35.651Z
Updated: 2024-08-03T17:30:07.387Z
Reserved: 2024-02-01T14:23:02.896Z
Link: CVE-2021-4435
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-02-04T20:15:45.657
Modified: 2024-11-21T06:37:43.400
Link: CVE-2021-4435
Redhat