npm Update
2961Warning Date
Severity Level
Warning Number
Target Sector
8 April, 2020
● Medium
2020-1113
All
Description:
npm has released security update to address a vulnerability in the following versions of node-weakauras-parser:
- 1.0.4
- 2.0.0
- 2.0.1
- 3.0.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Buffer overflow
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: