Vulnerability Description
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yarnpkg | Yarn | < 1.17.3 |
Related Weaknesses (CWE)
References
- https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.mdExploitThird Party Advisory
- https://hackerone.com/reports/640904Permissions RequiredThird Party Advisory
- https://yarnpkg.com/blog/2019/07/12/recommended-security-update/Vendor Advisory
- https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.mdExploitThird Party Advisory
- https://hackerone.com/reports/640904Permissions RequiredThird Party Advisory
- https://yarnpkg.com/blog/2019/07/12/recommended-security-update/Vendor Advisory
FAQ
What is CVE-2019-5448?
CVE-2019-5448 is a vulnerability with a CVSS score of 8.1 (HIGH). Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
How severe is CVE-2019-5448?
CVE-2019-5448 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5448?
Check the references section above for vendor advisories and patch information. Affected products include: Yarnpkg Yarn.