Bug 1165168 - (CVE-2020-8131) VUL-0: CVE-2020-8131: yarn: Arbitrary filesystem write allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution
(CVE-2020-8131)
VUL-0: CVE-2020-8131: yarn: Arbitrary filesystem write allows attackers to wr...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Jordi Massaguer
Security Team bot
https://smash.suse.de/issue/253693/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-02-27 14:27 UTC by Alexandros Toptsoglou
Modified: 2020-02-27 15:00 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2020-02-27 14:27:35 UTC
CVE-2020-8131

Arbitrary filesystem write vulnerability in Yarn 1.21.1 and earlier allows
attackers to write to any path on the filesystem and potentially lead to
arbitrary code execution by forcing the user to install a malicious package.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8131
http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8131.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8131
https://hackerone.com/reports/730239