CVE-2019-5448

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
References
Link Resource
https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md Exploit Third Party Advisory
https://hackerone.com/reports/640904 Permissions Required Third Party Advisory
https://yarnpkg.com/blog/2019/07/12/recommended-security-update/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*

History

03 Nov 2021, 18:27

Type Values Removed Values Added
CWE CWE-310 CWE-319

Information

Published : 2019-07-30 21:15

Updated : 2024-02-04 20:20


NVD link : CVE-2019-5448

Mitre link : CVE-2019-5448

CVE.ORG link : CVE-2019-5448


JSON object : View

Products Affected

yarnpkg

  • yarn
CWE
CWE-319

Cleartext Transmission of Sensitive Information

CWE-311

Missing Encryption of Sensitive Data