Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4435

Опубликовано: 20 сент. 2021
Источник: redhat
CVSS3: 7.7

Описание

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

Отчет

This flaw affects Windows versions only.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-426

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 2 лет назад

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

CVSS3: 7.7
nvd
около 2 лет назад

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

CVSS3: 7.7
debian
около 2 лет назад

An untrusted search path vulnerability was found in Yarn. When a victi ...

CVSS3: 7.7
github
около 2 лет назад

Yarn untrusted search path vulnerability

7.7 High

CVSS3