ZeroHour

CVE-2019-5448

PoC
CVSS 3.1
8.1 high
EPSS
<1%p50
Published
()
Modified
Description

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

Vendors
yarnpkg
Products
yarn
Weakness
CWE-311, CWE-319
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.