Bug 2361884 (CVE-2024-47829) - CVE-2024-47829 pnpm: pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
Summary: CVE-2024-47829 pnpm: pnpm uses the md5 path shortening function causes packet...
Keywords:
Status: NEW
Alias: CVE-2024-47829
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2361974 2361975 2361976
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-04-23 16:02 UTC by OSIDB Bzimport
Modified: 2025-04-24 12:58 UTC (History)
23 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-04-23 16:02:12 UTC
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0.


Note You need to log in before you can comment on or make changes to this bug.