Vulnerabilities (CVE)

Filtered by vendor Yarnpkg Subscribe
Filtered by product Yarn
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15608 1 Yarnpkg 1 Yarn 2020-03-21 4.3 MEDIUM 5.9 MEDIUM
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.