CVE-2021-4435: Yarn: untrusted search path
Published Feb 1, 2024
·Updated
An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
Affected Software
3 affected componentsFixes available
redhat/yarn<1.22.13
1.22.13
npm/yarn<1.22.13
1.22.13
yarnpkg yarn<1.22.13
Remediation
Event History
Feb 4, 2024
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-4435?
CVE-2021-4435 is classified as a high severity vulnerability due to its potential for executing malicious commands in user environments.
2
How do I fix CVE-2021-4435?
To fix CVE-2021-4435, update Yarn to version 1.22.13 or later.
3
What type of vulnerability is CVE-2021-4435?
CVE-2021-4435 is an untrusted search path vulnerability that affects the Yarn package manager.
4
Who is affected by CVE-2021-4435?
Users who run Yarn commands in directories containing attacker-controlled content are at risk from CVE-2021-4435.
5
What should I do if I suspect exploitation of CVE-2021-4435?
If you suspect exploitation of CVE-2021-4435, immediately update Yarn and review logs for any unauthorized activity.