CVE-2020-8131
Summary
| CVE | CVE-2020-8131 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-24 15:15:00 UTC |
| Updated | 2020-03-24 14:47:00 UTC |
| Description | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fixes arbitrary file write on fetch by arcanis · Pull Request #7831 · yarnpkg/yarn · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| HackerOne | MISC | hackerone.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180708 Debian Security Update for node-yarnpkg (CVE-2020-8131)