npm Updates
3173Warning Date
Severity Level
Warning Number
Target Sector
15 September, 2020
● High
2020-1774
All
Description:
npm has released a security updates to address multiple vulnerabilities in the following products:
- Azure DevOps
- renovate
- nagibabel
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
- Sensitive information disclosure
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: