icon

We found results for “

WS-2020-0127

Good to know:

icon
icon

Date: July 7, 2020

npm-registry-fetch before 4.0.5 and 8.1.1 is vulnerable to an information exposure vulnerability through log files.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Exposure of Sensitive Information to an Unauthorized Actor

CWE-200

Top Fix

icon

Upgrade Version

Upgrade to version Node-Kit - no_fix;flexxia/flexprimeng - dev-update-angularjs;flexxia/flexprimeng - dev-dependabot/npm_and_yarn/css/postcss/y18n-3.2.2;NpmLess - no_fix;nodejs - 9.5.0;nodejs - 10.22.0;nodejs - 14.6.0;nodejs - 12.18.3;SystemExt.Languages.Node.runtime.linux-arm - no_fix;npm-registry-fetch - 8.1.1;npm-registry-fetch - 4.0.5;NoNpm - no_fix;SystemExt.Languages.Node.runtime.linux-x64 - no_fix;Portable.Npm - no_fix;genenotebook - 0.1.2;SystemExt.Languages.Node.runtime.osx-x64 - no_fix;SystemExt.Languages.Node.runtime.linux-arm64 - no_fix;org.webjars.npm:npm-registry-fetch:4.0.7;org.webjars.npm:npm-registry-fetch:8.1.5;org.webjars.npm:evocateur__npm-registry-fetch:no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us