Known Vulnerabilities for products from Yarnpkg
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Yarnpkg".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-8131 json | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and po... | 7.5 - HIGH | 2020-02-24 | 2020-03-24 |
| CVE-2019-15608 json | The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a... | 5.9 - MEDIUM | 2020-03-15 | 2020-03-21 |
| CVE-2019-10773 json | In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem ... | 7.8 - HIGH | 2019-12-16 | 2023-11-07 |
| CVE-2019-5448 json | Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted aut... | 8.1 - HIGH | 2019-07-30 | 2021-11-03 |
| CVE-2018-12556 json | The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is... | 5.9 - MEDIUM | 2019-05-16 | 2019-05-21 |