Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
References
Link Resource
https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md Exploit Third Party Advisory
https://hackerone.com/reports/640904 Permissions Required Third Party Advisory
https://yarnpkg.com/blog/2019/07/12/recommended-security-update/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2019-07-30T20:15:57

Updated: 2019-07-30T20:15:57

Reserved: 2019-01-04T00:00:00


Link: CVE-2019-5448

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-07-30T21:15:11.523

Modified: 2021-11-03T18:27:45.383


Link: CVE-2019-5448

JSON object: View

cve-icon Redhat Information

No data.