Описание
Sensitive information exposure through logs in npm-registry-fetch
Affected versions of npm-registry-fetch are vulnerable to an information exposure vulnerability through log files. The cli supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.
Пакеты
Наименование
npm-registry-fetch
npm
Затронутые версииВерсия исправления
< 4.0.5
4.0.5
Наименование
npm-registry-fetch
npm
Затронутые версииВерсия исправления
>= 5.0.0, < 8.1.1
8.1.1
5.3 Medium
CVSS3
Дефекты
CWE-352
5.3 Medium
CVSS3
Дефекты
CWE-352