CVE-2021-4435

Description

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

Statement

This flaw affects Windows versions only.

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability,Access Control

Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands

There is the potential for arbitrary code execution with privileges of the vulnerable program.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

The program could be redirected to the wrong files, potentially triggering a crash or hang when the targeted file is too large or does not have the expected format.

Confidentiality

Technical Impact: Read Files or Directories

The program could send the output of unauthorized files to the attacker.

Acknowledgements

Red Hat would like to thank Paul Gerste (Sonar) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.