QID 980501
QID 980501: Nodejs (npm) Security Update for verdaccio (GHSA-78j5-gcmf-vqc8)
Security update has been released for verdaccio to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
What kind of vulnerability is it? Who is impacted?
Cross-Site Scripting XSS, malicious packages with content Javascript that might be executed in the User Interface stealing user credentials.
Solution
Has the problem been patched? What versions should users upgrade to?
Users that still using `v3` must upgrade to **>3.12.0** or those have no problem to migrate to a major version **>=4.0.0** also fix the issue.Workaround:
Is there a way for users to fix or remediate the vulnerability without upgrading?
No, the users must update.
Users that still using `v3` must upgrade to **>3.12.0** or those have no problem to migrate to a major version **>=4.0.0** also fix the issue.Workaround:
Is there a way for users to fix or remediate the vulnerability without upgrading?
No, the users must update.
Vendor References
- GHSA-78j5-gcmf-vqc8 -
github.com/advisories/GHSA-78j5-gcmf-vqc8
CVEs related to QID 980501
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-78j5-gcmf-vqc8 | verdaccio |
|