Description
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
Remediation
References
https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md
https://yarnpkg.com/blog/2019/07/12/recommended-security-update/
https://hackerone.com/reports/640904
Related Vulnerabilities
CVE-2021-34429 Vulnerability in maven package org.eclipse.jetty:jetty-webapp
CVE-2022-45383 Vulnerability in maven package org.jenkins-ci.plugins:support-core
CVE-2022-29546 Vulnerability in maven package org.codelibs:nekohtml
CVE-2015-6584 Vulnerability in maven package org.webjars:datatables
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap