Junglewise Threat Intelligence

CVE-2019-15608: Yarn package integrity validation TOCTOU race condition

CVE-2019-15608 · Severity: low · CVSS 3.1 · Published 2022-02-09

Technologies: yarn (npm). Vendors: npm.

Executive brief

Yarn is a package manager for JavaScript that manages dependencies and caches downloaded packages. A timing vulnerability in versions prior to 1.19.0 allows an attacker to inject malicious packages into the cache before integrity checks are performed, potentially causing applications to load compromised code during installation.

Technical details

The vulnerability is a TOCTOU (Time-of-Check-Time-of-Use) race condition in Yarn's package integrity validation, classified as CWE-367. The root cause is that package hash validation occurs before caching the package, but the cached version is not re-validated on subsequent reads. An attacker on the network or with local filesystem access can exploit this by modifying a package in transit or in the cache between the hash check and when it's actually used, leading to cache pollution. The attack requires network proximity or local filesystem access but no authentication. The vulnerability is fixed in Yarn 1.19.0, which validates stored package integrity before loading from cache.

Affected products

  • Yarn Yarn < 1.19.0

Timeline

  • 2020-03-15: disclosed
  • 2019: patched: Fixed in version 1.19.0
  • 2022-02-09: advisory

References

Related threats