The vendor explicitly states that these products are not affected by this CVE.
- pnpm as a component of Red Hat AMQ Broker 7
- pnpm as a component of Red Hat Build of Keycloak
- pnpm as a component of Red Hat JBoss Enterprise Application Platform 8
- pnpm as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- Summary
- A flaw was found in pnpm, a package manager. This vulnerability allows a remote attacker to serve malicious software packages if the `codeload.github.com` server is compromised or a user's machine configuration is tampered with. The issue arises because pnpm does not verify the integrity of dependencies downloaded from `https://codeload.github.com` against its lockfile. This could lead to the installation of unverified and potentially malicious code, resulting in arbitrary code execution on the affected system.
- Remediation
- No remediation text is recorded.
