CVE-2019-15608

CVE-2019-15608

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It’s not computed again when reading from the cache. This may lead to a cache pollution attack. This issue is fixed in 1.19.0.

Source: CVE-2019-15608

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다