{"id":"CVE-2019-5448","aliases":["GHSA-wqfc-cr59-h64p"],"url":"https://o3.security/vulnerability/CVE-2019-5448","summary":"Missing Encryption of Sensitive Data in yarn","details":"Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.","published":"2019-07-30T21:15:11.523Z","modified":"2026-07-08T20:57:33.790755Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"yarn","fixedVersion":"1.17.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://yarnpkg.com/blog/2019/07/12/recommended-security-update/"},{"type":"REPORT","url":"https://hackerone.com/reports/640904"},{"type":"EVIDENCE","url":"https://github.com/ChALkeR/notes/blob/master/Yarn-vuln.md"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:57:33.790755Z"}}