SB2020030304 - Improper validation of integrity check value in yarn package for dependency management
Published: March 3, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper validation of integrity check value (CVE-ID: N/A)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the software of the affected products does not check the integrity. A remote attacker can pollute yarn cache via a crafted yarn.lock file and place a malicious package into cache under any name/version, bypassing both integrity and hash checks in yarn.lock so that any future installs of that package will install the fake version (regardless of integrity and hashes).
Remediation
Install update from vendor's website.