Lucene search

K
nodejsUnknownNODEJS:1543
HistoryJul 07, 2020 - 7:03 p.m.

Sensitive Data Exposure

2020-07-0719:03:09
Unknown
www.npmjs.com
34

EPSS

0.001

Percentile

17.2%

Overview

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.

Recommendation

Upgrade to version 6.14.6 or later.

References