Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15095

Опубликовано: 07 июл. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1.9
CVSS3: 4.4

Описание

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and also to any generated log files.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

6.14.6+ds-1ubuntu1
eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

6.14.6+ds-1ubuntu1
esm-apps/noble

not-affected

6.14.6+ds-1ubuntu1
esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needs-triage

Показывать по

EPSS

Процентиль: 13%
0.00044
Низкий

1.9 Low

CVSS2

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
redhat
почти 5 лет назад

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.

CVSS3: 4.4
nvd
почти 5 лет назад

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.

CVSS3: 4.4
debian
почти 5 лет назад

Versions of the npm CLI prior to 6.14.6 are vulnerable to an informati ...

suse-cvrf
больше 4 лет назад

Security update for nodejs8

suse-cvrf
больше 4 лет назад

Security update for nodejs8

EPSS

Процентиль: 13%
0.00044
Низкий

1.9 Low

CVSS2

4.4 Medium

CVSS3