Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-12556

Опубликовано: 16 мая 2019
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yarnpkg:website:*:*:*:*:*:*:*:*
Версия до 2018-06-05 (включая)

EPSS

Процентиль: 56%
0.0034
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

CVSS3: 5.9
github
больше 3 лет назад

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

EPSS

Процентиль: 56%
0.0034
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-347