CVE-2019-10773

HIGH7.8EPSS 0.55%

Yarn Improper link resolution before file access (Link Following)

發布日:2020/2/14修改日:2026/3/13
也稱為:GHSA-5xf4-f2fq-f69jDEBIAN-CVE-2019-10773

描述

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

參考連結(10)