QID 982991

QID 982991: Nodejs (npm) Security Update for npm (GHSA-93f3-23rq-pjfp)

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like `<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>`. The password value is not redacted and is printed to stdout and also to any generated log files.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.4 severity.
  • CVSS V2 rated as Low - 1.9 severity.
  • Solution
    Customers are advised to refer to GHSA-93f3-23rq-pjfp for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982991

    Software Advisories
    Advisory ID Software Component Link
    GHSA-93f3-23rq-pjfp npm URL Logo github.com/advisories/GHSA-93f3-23rq-pjfp