MEDIUM
yarn: TOCTOU vulnerability leads to cache pollution
Published Mar 15, 2020
5.9
MEDIUMCVSS 3.1
EPSS 1.84%
Description
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
Affected products
- Vendor n/a Product Yarn Defaultn/a
- Version Fixed in 1.19.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Yarn | n/a |
|
No data.
Red Hat Quay 3
yarn
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 3 | yarn | Not affected | n/a |
yarn
npm
Introduced 0 Fixed 1.19.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | yarn | 0 | 1.19.0 |
Remediation
Red Hat mitigation
Run 'yarn cache clean' before installs.
References (9)
- https://access.redhat.com/security/cve/CVE-2019-15608 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1851875 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1051 Advisory
- https://github.com/advisories/GHSA-hjxc-462x-x77j Advisory
- https://github.com/yarnpkg/yarn/blob/master/CHANGELOG.md#1190 x_refsource_MISC
- https://github.com/yarnpkg/yarn/commit/0474b8c66a8ea298f5e4dedc67b2de464297ad1c x_refsource_MISC
- https://hackerone.com/reports/703138 x_refsource_MISCExploitMitigationThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15608
- https://www.cve.org/CVERecord?id=CVE-2019-15608
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-15608 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1851875 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1051 | Advisory | |
| https://github.com/advisories/GHSA-hjxc-462x-x77j | Advisory | |
| https://github.com/yarnpkg/yarn/blob/master/CHANGELOG.md#1190 | x_refsource_MISC | |
| https://github.com/yarnpkg/yarn/commit/0474b8c66a8ea298f5e4dedc67b2de464297ad1c | x_refsource_MISC | |
| https://hackerone.com/reports/703138 | x_refsource_MISCExploitMitigationThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15608 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-15608 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Mar 15, 2020
Updated Aug 5, 2024
Reserved Aug 26, 2019
Link CVE-2019-15608
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-1051 GHSA-HJXC-462X-X77J Assigner hackerone
Published Mar 15, 2020
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2022-1051