Description
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
Remediation
References
https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md
https://hackerone.com/reports/640904
https://yarnpkg.com/blog/2019/07/12/recommended-security-update/
Related Vulnerabilities
CVE-2023-34610 Vulnerability in maven package com.cedarsoftware:json-io
CVE-2021-22696 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-oauth2
CVE-2023-26155 Vulnerability in npm package node-qpdf
CVE-2022-25894 Vulnerability in maven package com.bstek.uflo:uflo-core
CVE-2022-25167 Vulnerability in maven package org.apache.flume:flume-parent