Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqfc-cr59-h64p

Опубликовано: 31 июл. 2019
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Missing Encryption of Sensitive Data in yarn

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

Пакеты

Наименование

yarn

npm
Затронутые версииВерсия исправления

< 1.17.3

1.17.3

EPSS

Процентиль: 29%
0.00107
Низкий

8.1 High

CVSS3

Дефекты

CWE-311
CWE-319

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

CVSS3: 8.1
nvd
больше 6 лет назад

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

CVSS3: 8.1
debian
больше 6 лет назад

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Da ...

EPSS

Процентиль: 29%
0.00107
Низкий

8.1 High

CVSS3

Дефекты

CWE-311
CWE-319