Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93f3-23rq-pjfp

Опубликовано: 07 июл. 2020
Источник: github
Github: Прошло ревью
CVSS3: 4.4

Описание

npm CLI exposing sensitive information through logs

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.

Пакеты

Наименование

npm

npm
Затронутые версииВерсия исправления

< 6.14.6

6.14.6

EPSS

Процентиль: 13%
0.00044
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 4.4
ubuntu
почти 5 лет назад

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.

CVSS3: 4.4
redhat
почти 5 лет назад

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.

CVSS3: 4.4
nvd
почти 5 лет назад

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.

CVSS3: 4.4
debian
почти 5 лет назад

Versions of the npm CLI prior to 6.14.6 are vulnerable to an informati ...

suse-cvrf
больше 4 лет назад

Security update for nodejs8

EPSS

Процентиль: 13%
0.00044
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-532