Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10773

Опубликовано: 16 дек. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*
Версия до 1.21.1 (исключая)

EPSS

Процентиль: 67%
0.00546
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

CVSS3: 7.8
redhat
около 6 лет назад

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

CVSS3: 7.8
debian
около 6 лет назад

In Yarn before 1.21.1, the package install functionality can be abused ...

CVSS3: 7.8
github
почти 6 лет назад

Yarn Improper link resolution before file access (Link Following)

EPSS

Процентиль: 67%
0.00546
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-59