npm Updates
3442Warning Date
Severity Level
Warning Number
Target Sector
7 June, 2020
● Medium
2020-1323
All
Description:
npm has released security updates to address a vulnerability in the following products:
- apollo-server
- prior to 2.4.12
- apollo-server-azure-functions
- prior to 2.4.12
- apollo-server-cache-memcached
- prior to 2.4.12
- apollo-server-core
- prior to 2.4.12
- apollo-server-cloud-function
- prior to 2.4.12
- apollo-server-cloudflare
- prior to 2.4.12
- apollo-server-express
- prior to 2.4.12
- apollo-server-fastify
- prior to 2.4.12
- apollo-server-hapi
- prior to 2.4.12
- apollo-server-koa
- prior to 2.4.12
- apollo-server-micro
- prior to 2.4.12
- apollo-server-lambda
- prior to 2.4.12
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Information disclosure.
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates:
- https://www.npmjs.com/advisories/1525
- https://www.npmjs.com/advisories/1526
- https://www.npmjs.com/advisories/1527
- https://www.npmjs.com/advisories/1528
- https://www.npmjs.com/advisories/1529
- https://www.npmjs.com/advisories/1530
- https://www.npmjs.com/advisories/1531
- https://www.npmjs.com/advisories/1532
- https://www.npmjs.com/advisories/1533
- https://www.npmjs.com/advisories/1534
- https://www.npmjs.com/advisories/1535
- https://www.npmjs.com/advisories/1536