Bug 33674 - yarnpkg new security issues CVE-2024-37890, CVE-2024-48949 and CVE-2024-12905
Summary: yarnpkg new security issues CVE-2024-37890, CVE-2024-48949 and CVE-2024-12905
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-10-25 11:35 CEST by Nicolas Salguero
Modified: 2025-06-19 05:15 CEST (History)
2 users (show)

See Also:
Source RPM: yarnpkg-1.22.22-0.10.8.2.2.mga10.src.rpm, yarnpkg-1.22.22-0.10.8.2.1.mga9.src.rpm
CVE: CVE-2020-7677, CVE-2021-43138, CVE-2022-3517, CVE-2024-37890, CVE-2024-48949, CVE-2022-37599, CVE-2023-26136, CVE-2023-46234, CVE-2024-12905, CVE-2024-4067, CVE-2025-48387
Status comment:


Attachments

Nicolas Salguero 2024-10-25 11:36:41 CEST

CVE: (none) => CVE-2024-37890, CVE-2024-48949
Source RPM: (none) => yarnpkg-1.22.22-0.10.8.2.2.mga10.src.rpm, yarnpkg-1.22.22-0.10.8.2.1.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 1 Marja Van Waes 2024-10-25 16:04:22 CEST
No registered maintainer, assigning to all.

CC'ing daviddavid who was the last one to touch it.

Assignee: bugsquad => pkg-bugs
CC: (none) => geiger.david68210, marja11

Comment 2 Nicolas Salguero 2025-04-22 13:39:08 CEST
Fedora has issued an advisory on April 11:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2UGLXZO6VIHGIITQTEUY5Q5YCAP2A4ZP/

Summary: yarnpkg new security issues CVE-2024-37890 and CVE-2024-48949 => yarnpkg new security issues CVE-2024-37890, CVE-2024-48949 and CVE-2024-12905

Nicolas Salguero 2025-04-22 13:39:19 CEST

CVE: CVE-2024-37890, CVE-2024-48949 => CVE-2024-37890, CVE-2024-48949, CVE-2024-12905

katnatek 2025-06-02 03:30:14 CEST

Assignee: pkg-bugs => j.alberto.vc

Comment 3 katnatek 2025-06-02 04:09:34 CEST
I think this was a few more simply, but one of fedora's patches fail for me

Assignee: j.alberto.vc => pkg-bugs

Comment 4 katnatek 2025-06-19 02:38:49 CEST
I rebase our spec &sources with fedora, I'm making a build test before send to mageia
katnatek 2025-06-19 05:15:38 CEST

CVE: CVE-2024-37890, CVE-2024-48949, CVE-2024-12905 => CVE-2020-7677, CVE-2021-43138, CVE-2022-3517, CVE-2024-37890, CVE-2024-48949, CVE-2022-37599, CVE-2023-26136, CVE-2023-46234, CVE-2024-12905, CVE-2024-4067, CVE-2025-48387


Note You need to log in before you can comment on or make changes to this bug.