VDB
Sign up
MEDIUM5.9

GHSA-hjxc-462x-x77j

TOCTOU Race Condition in Yarn

Quick fix

GHSA-hjxc-462x-x77j — yarn: upgrade to the fixed version with the command below.

npm install yarn@1.19.0

Details

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack. This issue is fixed in 1.19.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/yarn
Introduced in: 0Fixed in: 1.19.0
Fixnpm install yarn@1.19.0

References