Lucene search

K
cvelistHackeroneCVELIST:CVE-2019-5448
HistoryJul 30, 2019 - 8:15 p.m.

CVE-2019-5448

2019-07-3020:15:57
CWE-311
hackerone
www.cve.org
1

8 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.2%

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

CNA Affected

[
  {
    "product": "yarn",
    "vendor": "yarn",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in 1.17.3"
      }
    ]
  }
]

8 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.2%