CVE-2019-5448

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
References
Link Resource
https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md Exploit Third Party Advisory
https://yarnpkg.com/blog/2019/07/12/recommended-security-update/ Vendor Advisory
https://hackerone.com/reports/640904 Permissions Required Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*

Information

Published : 2019-07-30 09:15

Updated : 2021-11-03 06:27


NVD link : CVE-2019-5448

Mitre link : CVE-2019-5448

Products Affected
No products.
CWE
CWE-319

Cleartext Transmission of Sensitive Information