stable

yarnpkg-1.22.21-2.fc39

FEDORA-2024-28fc0c2ef4 created by smani 9 months ago for Fedora 39

Update to 1.22.21, add fixes for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2024-28fc0c2ef4

This update has been submitted for testing by smani.

9 months ago

This update's test gating status has been changed to 'ignored'.

9 months ago

This update has been pushed to testing.

9 months ago

This update has been submitted for stable by bodhi.

9 months ago

This update has been pushed to stable.

9 months ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
9 months ago
in testing
9 months ago
in stable
9 months ago
approved
9 months ago
BZ#2209317 CVE-2022-37599 yarnpkg: loader-utils: regular expression denial of service in interpolateName.js [fedora-all]
0
0
BZ#2220682 CVE-2023-26136 yarnpkg: tough-cookie: prototype pollution in cookie memstore [fedora-all]
0
0
BZ#2246633 CVE-2023-46234 yarnpkg: browserify-sign: upper bound check issue in dsaVerify leads to a signature forgery attack [fedora-all]
0
0

Automated Test Results