CVE-2019-5448

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
References
Link Resource
https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md Exploit Third Party Advisory
https://yarnpkg.com/blog/2019/07/12/recommended-security-update/ Vendor Advisory
https://hackerone.com/reports/640904 Permissions Required Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*

Information

Published : 2019-07-30 14:15

Updated : 2021-11-03 11:27


NVD link : CVE-2019-5448

Mitre link : CVE-2019-5448


JSON object : View

CWE
CWE-319

Cleartext Transmission of Sensitive Information

Advertisement

dedicated server usa

Products Affected

yarnpkg

  • yarn