Beveiligingsadvies

CVE-2019-15608

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-03-15 17:08:13
Laatst bijgewerkt 2024-08-05 00:49:13
Toegewezen door hackerone
CVSS-score geen score
Status PUBLISHED

Beschrijving

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.