ZeroHour

CVE-2020-8131

PoC
CVSS 3.1
7.5 high
EPSS
5%p92
Published
()
Modified
Description

Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

Vendors
yarnpkg
Products
yarn
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.