Описание
Missing Encryption of Sensitive Data in yarn
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
Пакеты
Наименование
yarn
npm
Затронутые версииВерсия исправления
< 1.17.3
1.17.3
Связанные уязвимости
CVSS3: 8.1
ubuntu
больше 6 лет назад
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
CVSS3: 8.1
nvd
больше 6 лет назад
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
CVSS3: 8.1
debian
больше 6 лет назад
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Da ...