Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
CVSS Information
N/A
Vulnerability Type
业务逻辑错误
Vulnerability Title
Yarn 竞争条件问题漏洞
Vulnerability Description
Yarn是一款开源的软件包安装、管理工具。 Yarn 1.19.0之前版本中软件包完整性检查存在竞争条件问题漏洞。该漏洞源于网络系统或产品在运行过程中,并发代码需要互斥地访问共享资源时,对于并发访问的处理不当。
CVSS Information
N/A
Vulnerability Type
N/A