Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
| Software | From | Fixed in |
|---|---|---|
| yarnpkg / yarn | - | 1.17.3 |
yarn
|
- | 1.17.3 |