ChALkeR

2 exploits Active since Jul 2019
CVE-2019-15608 WRITEUP MEDIUM WRITEUP
yarn <1.19.0 - Info Disclosure
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
CVSS 5.9
CVE-2019-5448 WRITEUP HIGH WRITEUP
Yarn < 1.17.3 - Cleartext Transmission
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
CVSS 8.1