Understanding filesystem takeover vulnerabilities in npm JavaScript package manager
CYBERSECURITY FEATURED ANALYSIS

Understanding filesystem takeover vulnerabilities in npm JavaScript package manager

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

On the 11th of December, 2019 a security vulnerability which extends to all major JavaScript package managers (npm, yarn and pnpm) was publicly disclosed. This vulnerability, discovered by security researcher Daniel Ruf, …

On the 11th of December, 2019 a security vulnerability which extends to all major JavaScript package managers (npm, yarn and pnpm) was publicly disclosed. This vulnerability, discovered by security researcher Daniel Ruf, allows malicious actors to apply varied tactics of arbitrary file overwrites.