Записи yarnpkg
8 опубликованных записей вендора yarnpkg.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-426 Untrusted Search Path1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2020-8131Эксплойта нет | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead yarnpkg · yarn · CWE-22 | Высокая7,5 | — | 5,2 % | 24 февр. 2020 г. |
32Наблюдать | CVE-2019-5448Эксплойта нет | Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication datyarnpkg · yarn · CWE-311 | Высокая8,1 | — | 0,7 % | 30 июл. 2019 г. |
31Наблюдать | CVE-2019-10773Эксплойта нет | In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using speciayarnpkg · yarn · CWE-59 | Высокая7,8 | — | 1,5 % | 16 дек. 2019 г. |
31Наблюдать | CVE-2021-4435Эксплойта нет | Yarn: untrusted search pathyarnpkg · yarn · CWE-426 | Высокая7,8 | — | 0,3 % | 4 февр. 2024 г. |
24Наблюдать | CVE-2019-15608Эксплойта нет | The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cacyarnpkg · yarn · CWE-840 | Средняя5,9 | — | 1,8 % | 15 мар. 2020 г. |
24Наблюдать | CVE-2018-12556Эксплойта нет | The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any yarnpkg · website · CWE-347 | Средняя5,9 | — | 1,8 % | 16 мая 2019 г. |
21Наблюдать | CVE-2025-8262Эксплойта нет | yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redosyarnpkg · yarn · CWE-400 | Средняя5,3 | — | 0,7 % | 28 июл. 2025 г. |
19Наблюдать | CVE-2025-9308Эксплойта нет | yarnpkg Yarn request-manager.js setOptions redosyarnpkg · yarn · CWE-400 | Средняя4,8 | — | 0,2 % | 21 авг. 2025 г. |
- CVE-2020-813132Наблюдать
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %yarnpkg · yarn24 февр. 2020 г.
- CVE-2019-544832Наблюдать
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication dat
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %yarnpkg · yarn30 июл. 2019 г.
- CVE-2019-1077331Наблюдать
In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specia
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %yarnpkg · yarn16 дек. 2019 г.
- CVE-2021-443531Наблюдать
Yarn: untrusted search path
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %yarnpkg · yarn4 февр. 2024 г.
- CVE-2019-1560824Наблюдать
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cac
СредняяCVSS 5,9Эксплойта нетEPSS 2 %yarnpkg · yarn15 мар. 2020 г.
- CVE-2018-1255624Наблюдать
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any
СредняяCVSS 5,9Эксплойта нетEPSS 2 %yarnpkg · website16 мая 2019 г.
- CVE-2025-826221Наблюдать
yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos
СредняяCVSS 5,3Эксплойта нетEPSS 1 %yarnpkg · yarn28 июл. 2025 г.
- CVE-2025-930819Наблюдать
yarnpkg Yarn request-manager.js setOptions redos
СредняяCVSS 4,8Эксплойта нетEPSS 0 %yarnpkg · yarn21 авг. 2025 г.