CVE-2020-8131
Published Feb 24, 2020
Last updated 5 years ago
Overview
- Description
- Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
- Source
- support@hackerone.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 5.9
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABF332FA-DFF6-4F4E-A531-937B2907B6A3", "versionEndIncluding": "1.21.1" } ], "operator": "OR" } ] } ]