VDB
Sign up
HIGH8.1

GHSA-wqfc-cr59-h64p

Missing Encryption of Sensitive Data in yarn

Quick fix

GHSA-wqfc-cr59-h64p — yarn: upgrade to the fixed version with the command below.

npm install yarn@1.17.3

Details

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/yarn
Introduced in: 0Fixed in: 1.17.3
Fixnpm install yarn@1.17.3

References