Описание
PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.
Ссылки
- Patch
- Release Notes
- ExploitThird Party Advisory
- Patch
- Release Notes
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.15.1 (исключая)
Одновременно
cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00642
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-426
Связанные уязвимости
CVSS3: 8.8
debian
почти 4 года назад
PNPM v6.15.1 and below was discovered to contain an untrusted search p ...
EPSS
Процентиль: 70%
0.00642
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-426