Untrusted Search Path Vulnerability in Yarn
CVE-2021-4435

7.7HIGH

Key Information:

Vendor

Fedora

Vendor
CVE Published:
4 February 2024

What is CVE-2021-4435?

An untrusted search path vulnerability exists in Yarn that allows for the execution of unverified commands when a user runs specific Yarn commands in directories containing content controlled by an attacker. This could lead to unexpected command executions, posing a significant risk to environments where Yarn operates. Proper caution and updates are vital to mitigate this vulnerability, particularly in shared or public directories.

Affected Version(s)

yarn 1.22.13

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Gerste (Sonar) for reporting this issue.
.