Skip to main content

Vendor/product archive

yarnpkg / website CVEs

Beta · best-effort

1 CVEs tagged to yarnpkg / website0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2018-12556

Published May 16, 2019

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1