CVE-2019-10773
Summary
| CVE | CVE-2019-10773 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-16 20:15:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 30 Update: nodejs-yarn-1.21.1-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Fixes bin overwrites (#7755) · yarnpkg/yarn@039bafd · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Page not found | Snyk | snyk.io | ||
| [SECURITY] Fedora 31 Update: nodejs-yarn-1.21.1-1.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 30 Update: nodejs-yarn-1.21.1-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 31 Update: nodejs-yarn-1.21.1-1.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Invalid vulnerability | MISC | snyk.io | Broken Link |
| globally-installed package overwrites an existing binary in the target install location · Issue #7761 · yarnpkg/yarn · GitHub | CONFIRM | github.com | Exploit, Third Party Advisory |
| binary planting and arbitrary file (over)write vulnerabilities in npm, pnpm and yarn | Blog of Daniel Ruf | MISC | blog.daniel-ruf.de | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981590 Nodejs (npm) Security Update for yarn (GHSA-5xf4-f2fq-f69j)