Fast, reliable, and secure dependency management.
Update Information:
Update to 1.22.21, add fixes for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234.
* Mon Feb 19 2024 Sandro Mani
[ 1 ] Bug #2209317 - CVE-2022-37599 yarnpkg: loader-utils: regular expression denial of service in interpolateName.js [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2209317
[ 2 ] Bug #2220682 - CVE-2023-26136 yarnpkg: tough-cookie: prototype pollution in cookie memstore [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2220682
[ 3 ] Bug #2246633 - CVE-2023-46234 yarnpkg: browserify-sign: upper bound check issue in dsaVerify leads to a signature forgery attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2246633
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-28fc0c2ef4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html
Get the latest Linux and open source security news straight to your inbox.