Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mxx-g9vw-r875

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

EPSS

Процентиль: 56%
0.0034
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

CVSS3: 5.9
nvd
больше 6 лет назад

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

EPSS

Процентиль: 56%
0.0034
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-347