CVE-2020-8131

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
24/02/2020
Last modified:
24/03/2020

Description

Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:* 1.21.1 (including)