QID 981590
QID 981590: Nodejs (npm) Security Update for yarn (GHSA-5xf4-f2fq-f69j)
In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5xf4-f2fq-f69j for updates pertaining to this vulnerability.
Vendor References
- GHSA-5xf4-f2fq-f69j -
github.com/advisories/GHSA-5xf4-f2fq-f69j
CVEs related to QID 981590
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5xf4-f2fq-f69j | yarn |
|