QID 980214
QID 980214: Nodejs (npm) Security Update for yarn (GHSA-wqfc-cr59-h64p)
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wqfc-cr59-h64p for updates pertaining to this vulnerability.
Vendor References
- GHSA-wqfc-cr59-h64p -
github.com/advisories/GHSA-wqfc-cr59-h64p
CVEs related to QID 980214
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wqfc-cr59-h64p | yarn |
|