CVE-2019-5448: High severity yarn vulnerability
Published Jul 30, 2019
·Updated
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
Affected Software
1 affected component
yarnpkg yarn<1.17.3
Event History
Jul 30, 2019
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-5448.
2
What is the severity of CVE-2019-5448?
The severity of CVE-2019-5448 is high.
3
What is the description of CVE-2019-5448?
CVE-2019-5448 is a vulnerability in Yarn before 1.17.3 that allows unencrypted authentication data to be sent over the network due to HTTP URLs in the lockfile.
4
How does CVE-2019-5448 affect Yarnpkg?
CVE-2019-5448 affects Yarnpkg versions up to and excluding 1.17.3.
5
What can I do to fix CVE-2019-5448?
To fix CVE-2019-5448, update your Yarnpkg version to 1.17.3 or later as recommended in the security update.