yarnpkg kayıtları
yarnpkg üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-426 Untrusted Search Path1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2020-8131İstismar yok | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead yarnpkg · yarn · CWE-22 | Yüksek7,5 | — | %5,2 | 24 Şub 2020 |
32İzleyin | CVE-2019-5448İstismar yok | Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication datyarnpkg · yarn · CWE-311 | Yüksek8,1 | — | %0,7 | 30 Tem 2019 |
31İzleyin | CVE-2019-10773İstismar yok | In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using speciayarnpkg · yarn · CWE-59 | Yüksek7,8 | — | %1,5 | 16 Ara 2019 |
31İzleyin | CVE-2021-4435İstismar yok | Yarn: untrusted search pathyarnpkg · yarn · CWE-426 | Yüksek7,8 | — | %0,3 | 4 Şub 2024 |
24İzleyin | CVE-2019-15608İstismar yok | The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cacyarnpkg · yarn · CWE-840 | Orta5,9 | — | %1,8 | 15 Mar 2020 |
24İzleyin | CVE-2018-12556İstismar yok | The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any yarnpkg · website · CWE-347 | Orta5,9 | — | %1,8 | 16 May 2019 |
21İzleyin | CVE-2025-8262İstismar yok | yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redosyarnpkg · yarn · CWE-400 | Orta5,3 | — | %0,7 | 28 Tem 2025 |
19İzleyin | CVE-2025-9308İstismar yok | yarnpkg Yarn request-manager.js setOptions redosyarnpkg · yarn · CWE-400 | Orta4,8 | — | %0,2 | 21 Ağu 2025 |
- CVE-2020-813132İzleyin
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead
YüksekCVSS 7,5İstismar yokEPSS %5yarnpkg · yarn24 Şub 2020
- CVE-2019-544832İzleyin
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication dat
YüksekCVSS 8,1İstismar yokEPSS %1yarnpkg · yarn30 Tem 2019
- CVE-2019-1077331İzleyin
In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specia
YüksekCVSS 7,8İstismar yokEPSS %2yarnpkg · yarn16 Ara 2019
- CVE-2021-443531İzleyin
Yarn: untrusted search path
YüksekCVSS 7,8İstismar yokEPSS %0yarnpkg · yarn4 Şub 2024
- CVE-2019-1560824İzleyin
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cac
OrtaCVSS 5,9İstismar yokEPSS %2yarnpkg · yarn15 Mar 2020
- CVE-2018-1255624İzleyin
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any
OrtaCVSS 5,9İstismar yokEPSS %2yarnpkg · website16 May 2019
- CVE-2025-826221İzleyin
yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos
OrtaCVSS 5,3İstismar yokEPSS %1yarnpkg · yarn28 Tem 2025
- CVE-2025-930819İzleyin
yarnpkg Yarn request-manager.js setOptions redos
OrtaCVSS 4,8İstismar yokEPSS %0yarnpkg · yarn21 Ağu 2025