CVE-2018-12556
Published May 16, 2019The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of…
Vendor/product archive
1 CVEs tagged to yarnpkg / website — 0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of…