Beveiligingsadvies

CVE-2019-5448

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-07-30 20:15:57
Laatst bijgewerkt 2024-08-04 19:54:53
Toegewezen door hackerone
CVSS-score geen score
Status PUBLISHED

Beschrijving

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.