Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpwj-fcr6-x34c

Опубликовано: 04 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Yarn untrusted search path vulnerability

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

Пакеты

Наименование

yarn

npm
Затронутые версииВерсия исправления

< 1.22.13

1.22.13

EPSS

Процентиль: 16%
0.00051
Низкий

7.7 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 2 лет назад

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

CVSS3: 7.7
redhat
больше 4 лет назад

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

CVSS3: 7.7
nvd
около 2 лет назад

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

CVSS3: 7.7
debian
около 2 лет назад

An untrusted search path vulnerability was found in Yarn. When a victi ...

EPSS

Процентиль: 16%
0.00051
Низкий

7.7 High

CVSS3

Дефекты

CWE-426