Arbitrary Symlink Vulnerability in Yarn Package Manager
CVE-2019-10773

7.8HIGH

Key Information:

Vendor

Yarnpkg

Status
Vendor
CVE Published:
16 December 2019

What is CVE-2019-10773?

A design flaw in Yarn prior to version 1.21.1 allows attackers to exploit the package install functionality, crafting malicious 'bin' keys that can generate arbitrary symlinks on the host filesystem. This vulnerability poses a risk as it can lead to the overwriting of existing files, contingent on the permissions of the user executing Yarn commands. This highlights critical security implications for systems utilizing Yarn for package management, potentially compromising system integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Yarn All versions prior to version 1.21.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.