In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2019-12-16T19:31:34

Updated: 2020-02-11T20:06:06

Reserved: 2019-04-03T00:00:00


Link: CVE-2019-10773

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-12-16T20:15:14.477

Modified: 2023-11-07T03:02:33.657


Link: CVE-2019-10773

JSON object: View

cve-icon Redhat Information

No data.

CWE