npm Updates
3064Warning Date
Severity Level
Warning Number
Target Sector
9 June, 2021
● Critical
2021-3013
All
Description:
npm has released security updates to address multiple vulnerabilities in the following products:
- normalize-url
- Versions before 4.5.1
- js-extend
- 0.0.1 - 1.0.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS)
- prototype-pollution attack
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: