Information on source package node-yarnpkg

Available versions

ReleaseVersion
buster1.13.0-1+deb10u1
bullseye1.22.10+~cs22.25.14-3
bookworm1.22.19+~cs24.27.18-2+deb12u1
trixie4.0.2+dfsg-2
sid4.0.2+dfsg-2

Open issues

BugbusterbullseyebookwormtrixiesidDescription
CVE-2021-4435vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn untrusted search path vulnerability was found in Yarn. When a victi ...
CVE-2020-8131vulnerable (no DSA)fixedfixedfixedfixedArbitrary filesystem write vulnerability in Yarn before 1.22.0 allows ...
CVE-2019-15608vulnerable (no DSA)fixedfixedfixedfixedThe package integrity validation in yarn < 1.19.0 contains a TOCTOU vu ...
CVE-2019-10773vulnerable (no DSA)fixedfixedfixedfixedIn Yarn before 1.21.1, the package install functionality can be abused ...

Resolved issues

BugDescription
CVE-2019-5448Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Da ...

Search for package or bug name: Reporting problems