npm Updates
2781Warning Date
Severity Level
Warning Number
Target Sector
30 July, 2020
● Medium
2020-1568
All
Description:
npm released security updates to address two vulnerabilities in the following products:
- auth0
- Versions prior to 2.27.1
- Elliptic
- Versions prior to 6.5.3
Threats:
An attacker could exploit these vulnerabilities by causing the following:
- Sensitive information disclosure
- Buffer overflow
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: