You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In brief: It accepts signatures from all public keys in the default keyring that the user running the script is using. It would be better to make sure that only a signature by yarn's public key is accepted.
The text was updated successfully, but these errors were encountered:
This is a security related defect, described in detail at https://neopg.io/blog/yarn-signature-bypass/ and got CVE-2018-12556 assigned.
The current code still looks unchanged and it is assumed it still has this problem
https://github.com/yarnpkg/website/blob/3dd78bf17ae02ec2f03b899240869f943c30a0e5/install.sh#L49
In brief: It accepts signatures from all public keys in the default keyring that the user running the script is using. It would be better to make sure that only a signature by yarn's public key is accepted.
The text was updated successfully, but these errors were encountered: