Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-15608

Опубликовано: 15 мар. 2020
Источник: debian
EPSS Низкий

Описание

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-yarnpkgfixed1.19.1-1package
node-yarnpkgno-dsabusterpackage

Примечания

  • https://hackerone.com/reports/703138

EPSS

Процентиль: 64%
0.00463
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 4.4
redhat
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 5.9
nvd
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 5.9
github
почти 4 года назад

TOCTOU Race Condition in Yarn

EPSS

Процентиль: 64%
0.00463
Низкий