CVE-2019-5448
PoC —CVSS 3.1
8.1 high
EPSS
<1%p50
Published
()
Modified
Description
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
- Vendors
- yarnpkg
- Products
- yarn
- Weakness
- CWE-311, CWE-319
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.