QID 284943
Date Published: 2024-02-29
QID 284943: Fedora Security Update for yarnpkg (FEDORA-2024-5ecc250449)
Fedora has released a security update for yarnpkg to fix the vulnerabilities.
Affected OS:
Fedora 38
QID Detection Logic(Authenticated):
This QID checks for vulnerable packages using regex on the output of 'rpm -qa' command.
Malicious users could use this vulnerability to change partial contents or configuration on the system. Additionally this vulnerability can also be used to cause a limited denial of service in the form of interruptions in resource availability.
Solution
Refer to Fedora security advisory Fedora 38 for updates and patch information.
Vendor References
- FEDORA-2024-5ecc250449 -
bodhi.fedoraproject.org/updates/FEDORA-2024-5ecc250449
CVEs related to QID 284943
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FEDORA-2024-5ecc250449 | Fedora 38 |
|