Bug 1816261 (CVE-2020-8131) - CVE-2020-8131 yarn: Arbitrary filesystem write via tar expansion
Summary: CVE-2020-8131 yarn: Arbitrary filesystem write via tar expansion
Alias: CVE-2020-8131
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1816262
Blocks: 1816263
TreeView+ depends on / blocked
Reported: 2020-03-23 16:56 UTC by Pedro Sampaio
Modified: 2021-02-16 20:25 UTC (History)
4 users (show)

Fixed In Version: yarn 1.22
Doc Type: If docs needed, set a value
Doc Text:
An arbitrary file write flaw was found in Yarn. This flaw allows an attacker to write files to a user’s system in unexpected places, potentially leading to remote code execution. The attacker would need to first trick a developer into installing a malicious package.
Clone Of:
Last Closed: 2021-02-04 20:41:59 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2021:0420 0 None None None 2021-02-04 16:14:38 UTC

Description Pedro Sampaio 2020-03-23 16:56:10 UTC
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

Upstream patch:




Comment 1 Pedro Sampaio 2020-03-23 16:58:09 UTC
Created nodejs-yarn tracking bugs for this issue:

Affects: fedora-all [bug 1816262]

Comment 5 Jason Shepherd 2020-03-24 23:50:36 UTC

Normally yarn allows packages to run postinstall scripts which can write arbitrary files to the users system. This vulnerability allows an attacker to better hide the attack and also allow arbitrary file write when postinstall scripts are disabled with the '--ignore-scripts' option of 'yarn install'.

Comment 6 errata-xmlrpc 2021-02-04 16:14:36 UTC
This issue has been addressed in the following products:

  Red Hat Quay 3

Via RHSA-2021:0420 https://access.redhat.com/errata/RHSA-2021:0420

Comment 7 Product Security DevOps Team 2021-02-04 20:41:59 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):


Note You need to log in before you can comment on or make changes to this bug.