Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-15608

Опубликовано: 26 фев. 2020
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

A flaw was found in Yarn. The package integrity validation in Yarn contains a time-of-check to time-of-use (TOCTOU) vulnerability where the hash is computed before writing a package to cache and is not computed again when reading from the cache. This flaw may lead to a cache pollution attack. The highest threat from this vulnerability is to integrity.

Меры по смягчению последствий

Run 'yarn cache clean' before installs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Quay 3yarnNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=1851875yarn: TOCTOU vulnerability leads to cache pollution

EPSS

Процентиль: 64%
0.00463
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 5.9
nvd
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

CVSS3: 5.9
debian
почти 6 лет назад

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vu ...

CVSS3: 5.9
github
почти 4 года назад

TOCTOU Race Condition in Yarn

EPSS

Процентиль: 64%
0.00463
Низкий

4.4 Medium

CVSS3