Описание
An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | needs-triage | |
| esm-apps/focal | needed | |
| esm-apps/jammy | needed | |
| esm-apps/noble | needs-triage | |
| focal | ignored | end of standard support, was needed |
| jammy | needed | |
| mantic | not-affected | 1.22.19+~cs24.27.18-4 |
| noble | needs-triage | |
| oracular | ignored | end of life, was needs-triage |
Показывать по
Ссылки на источники
7.7 High
CVSS3
Связанные уязвимости
An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
An untrusted search path vulnerability was found in Yarn. When a victi ...
7.7 High
CVSS3