VulnerabilityModified
CVE-2019-5448
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
HIGH 8.1EPSS 0.67%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-311, CWE-319
- Affected
- yarnpkg/yarn
- Source
- support@hackerone.com
References
- https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.mdExploit, Third Party Advisory
- https://hackerone.com/reports/640904Permissions Required, Third Party Advisory
- https://yarnpkg.com/blog/2019/07/12/recommended-security-update/Vendor Advisory
- https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.mdExploit, Third Party Advisory
- https://hackerone.com/reports/640904Permissions Required, Third Party Advisory
- https://yarnpkg.com/blog/2019/07/12/recommended-security-update/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.