Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-10773

Опубликовано: 16 дек. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

1.22.19+~cs24.27.18-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

1.22.19+~cs24.27.18-1
esm-apps/resolute

not-affected

1.22.19+~cs24.27.18-1
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage

Показывать по

EPSS

Процентиль: 73%
0.01518
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 6 лет назад

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

CVSS3: 7.8
nvd
больше 6 лет назад

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

CVSS3: 7.8
debian
больше 6 лет назад

In Yarn before 1.21.1, the package install functionality can be abused ...

CVSS3: 7.8
github
больше 6 лет назад

Yarn Improper link resolution before file access (Link Following)

EPSS

Процентиль: 73%
0.01518
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3