Lucene search

K
osvGoogleOSV:GHSA-93F3-23RQ-PJFP
HistoryJul 07, 2020 - 6:56 p.m.

npm CLI exposing sensitive information through logs

2020-07-0718:56:16
Google
osv.dev
14

EPSS

0.001

Percentile

17.2%

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.