Bug 33674 - yarnpkg new security issues CVE-2024-37890 and CVE-2024-48949
Summary: yarnpkg new security issues CVE-2024-37890 and CVE-2024-48949
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-10-25 11:35 CEST by Nicolas Salguero
Modified: 2024-10-25 16:04 CEST (History)
2 users (show)

See Also:
Source RPM: yarnpkg-1.22.22-0.10.8.2.2.mga10.src.rpm, yarnpkg-1.22.22-0.10.8.2.1.mga9.src.rpm
CVE: CVE-2024-37890, CVE-2024-48949
Status comment:


Attachments

Nicolas Salguero 2024-10-25 11:36:41 CEST

CVE: (none) => CVE-2024-37890, CVE-2024-48949
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => yarnpkg-1.22.22-0.10.8.2.2.mga10.src.rpm, yarnpkg-1.22.22-0.10.8.2.1.mga9.src.rpm

Comment 1 Marja Van Waes 2024-10-25 16:04:22 CEST
No registered maintainer, assigning to all.

CC'ing daviddavid who was the last one to touch it.

Assignee: bugsquad => pkg-bugs
CC: (none) => geiger.david68210, marja11


Note You need to log in before you can comment on or make changes to this bug.