Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjxc-462x-x77j

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

TOCTOU Race Condition in Yarn

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack. This issue is fixed in 1.19.0.

Пакеты

Наименование

yarn

npm
Затронутые версииВерсия исправления

< 1.19.0

1.19.0

EPSS

Процентиль: 64%
0.00463
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 4.4
redhat
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 5.9
nvd
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 5.9
debian
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vu ...

EPSS

Процентиль: 64%
0.00463
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-367