CVE-2020-8131: Path Traversal
An arbitrary file write flaw was found in Yarn. This flaw allows an attacker to write files to a user’s system in unexpected places, potentially leading to remote code execution. The attacker would need to first trick a developer into installing a malicious package.
Other sources
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/yarnto a version that resolves this vulnerability.Fixed in 1.22 - Upgrade
Upgrade
yarnpkg/yarnto a version that resolves this vulnerability.Fixed in 1.22.0
Event History
Frequently Asked Questions
What is CVE-2020-8131?
CVE-2020-8131 is an arbitrary filesystem write vulnerability in Yarn before version 1.22.0.
What is the severity of CVE-2020-8131?
The severity of CVE-2020-8131 is high (severity value: 7).
How does CVE-2020-8131 allow attackers to write files?
CVE-2020-8131 allows attackers to write files to a user's system in unexpected places potentially leading to remote code execution.
How can an attacker exploit CVE-2020-8131?
An attacker would need to trick a developer into installing a malicious package to exploit CVE-2020-8131.
How can I fix CVE-2020-8131?
To fix CVE-2020-8131, update Yarn to version 1.22.0 or later.