7.5
CVSSv3

CVE-2020-8131

Published: 24/02/2020 Updated: 24/03/2020
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Arbitrary filesystem write vulnerability in Yarn prior to 1.22.0 allows malicious users to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yarnpkg yarn

Vendor Advisories

Synopsis Moderate: Red Hat Quay v340 security update Type/Severity Security Advisory: Moderate Topic Red Hat Quay 340 is now available with bug fixes and variousenhancementsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVS ...
Debian Bug report logs - #952912 node-yarnpkg: CVE-2020-8131 Package: src:node-yarnpkg; Maintainer for src:node-yarnpkg is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 1 Mar 2020 20:27:01 UTC Severity: important Tags: s ...