OSV 1.4.0 · github-reviewed · 修改于 2021-08-18 03:40
发布时间
2019-07-31 12:22
GitHub 审查时间
2019-07-31 11:41
NVD 发布时间
2019-07-31 05:15
源文件
advisories/github-reviewed/2019/07/GHSA-wqfc-cr59-h64p/GHSA-wqfc-cr59-h64p.json
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.