Описание
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies entry when the committed env lockfile contained matching pnpm and @pnpm/exe versions. A malicious repository could therefore commit package-manager lockfile package records and snapshots that bypassed fresh package-manager resolution, then cause pnpm to install and execute bytes selected by that committed lockfile state during automatic version switching. This vulnerability is fixed in 10.34.2 and 11.5.3.
A flaw was found in pnpm, a package manager. This vulnerability allows a remote attacker to achieve arbitrary code execution by committing a specially crafted package-manager lockfile (pnpm-lock.yaml) to a repository. When pnpm is executed, it trusts an already resolved packageManagerDependencies entry, enabling the malicious lockfile to bypass standard package resolution. This can cause pnpm to install and execute attacker-controlled code during automatic version switching.
Отчет
This is an Important arbitrary code execution flaw in pnpm, a package manager used in Red Hat products. The vulnerability arises from pnpm's trust in pre-resolved package manager metadata within pnpm-lock.yaml, allowing a malicious repository to bypass standard package resolution. This can lead to the execution of attacker-controlled code when pnpm is used to install dependencies from such a repository, posing a significant supply chain risk.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | pnpm | Not affected | ||
| Red Hat Build of Keycloak | pnpm | Affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | pnpm | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | pnpm | Not affected |
Показывать по
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies entry when the committed env lockfile contained matching pnpm and @pnpm/exe versions. A malicious repository could therefore commit package-manager lockfile package records and snapshots that bypassed fresh package-manager resolution, then cause pnpm to install and execute bytes selected by that committed lockfile state during automatic version switching. This vulnerability is fixed in 10.34.2 and 11.5.3.
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persi ...
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
8.8 High
CVSS3