We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-47829

pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting



Description

pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0.

Reserved 2024-10-03 | Published 2025-04-23 | Updated 2025-04-23 | Assigner GitHub_M


MEDIUM: 6.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Problem types

CWE-328: Use of Weak Hash

Product status

< 10.0.0
affected

References

github.com/pnpm/pnpm/security/advisories/GHSA-8cc4-rfj6-fhg4

cve.org (CVE-2024-47829)

nvd.nist.gov (CVE-2024-47829)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-47829

Support options

Helpdesk Chat, Email, Knowledgebase