Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdxZmMtY3I1OS1oNjRw
Missing Encryption of Sensitive Data in yarn
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
Permalink: https://github.com/advisories/GHSA-wqfc-cr59-h64pJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdxZmMtY3I1OS1oNjRw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 5 years ago
Updated: almost 2 years ago
CVSS Score: 8.1
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Percentage: 0.00496
EPSS Percentile: 0.76542
Identifiers: GHSA-wqfc-cr59-h64p, CVE-2019-5448
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-5448
- https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md
- https://hackerone.com/reports/640904
- https://yarnpkg.com/blog/2019/07/12/recommended-security-update/
- https://github.com/advisories/GHSA-wqfc-cr59-h64p
Blast Radius: 39.3
Affected Packages
npm:yarn
Dependent packages: 3,296Dependent repositories: 71,861
Downloads: 21,015,492 last month
Affected Version Ranges: < 1.17.3
Fixed in: 1.17.3
All affected versions: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.15.1, 0.16.0, 0.16.1, 0.17.0, 0.17.2, 0.17.3, 0.17.4, 0.17.5, 0.17.6, 0.17.7, 0.17.8, 0.17.9, 0.17.10, 0.18.0, 0.18.1, 0.18.2, 0.19.0, 0.19.1, 0.20.0, 0.20.3, 0.20.4, 0.21.0, 0.21.1, 0.21.2, 0.21.3, 0.22.0, 0.23.0, 0.23.1, 0.23.2, 0.23.3, 0.23.4, 0.24.0, 0.24.1, 0.24.2, 0.24.3, 0.24.4, 0.24.5, 0.24.6, 0.25.1, 0.25.2, 0.25.3, 0.25.4, 0.26.0, 0.26.1, 0.27.0, 0.27.1, 0.27.2, 0.27.3, 0.27.4, 0.27.5, 0.28.1, 0.28.4, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.2.0, 1.2.1, 1.3.1, 1.3.2, 1.4.0, 1.5.0, 1.5.1, 1.6.0, 1.7.0, 1.8.0, 1.9.1, 1.9.2, 1.9.4, 1.10.0, 1.10.1, 1.11.0, 1.11.1, 1.12.0, 1.12.1, 1.12.3, 1.13.0, 1.14.0, 1.15.0, 1.15.1, 1.15.2, 1.16.0, 1.17.0, 1.17.1, 1.17.2
All unaffected versions: 1.17.3, 1.18.0, 1.19.0, 1.19.1, 1.19.2, 1.21.0, 1.21.1, 1.22.0, 1.22.1, 1.22.4, 1.22.5, 1.22.6, 1.22.7, 1.22.8, 1.22.9, 1.22.10, 1.22.11, 1.22.12, 1.22.13, 1.22.14, 1.22.15, 1.22.16, 1.22.17, 1.22.18, 1.22.19, 1.22.20, 1.22.21, 1.22.22, 2.4.3