An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-02-04T19:16:35.651Z

Updated: 2024-08-03T17:30:07.387Z

Reserved: 2024-02-01T14:23:02.896Z

Link: CVE-2021-4435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-02-04T20:15:45.657

Modified: 2024-02-13T00:38:56.303

Link: CVE-2021-4435

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-09-20T00:00:00Z

Links: CVE-2021-4435 - Bugzilla