npm Update
2874Warning Date
Severity Level
Warning Number
Target Sector
20 August, 2020
● Medium
2020-1657
All
Description:
npm released security update to address a vulnerability in the following product:
- auth0-lock
- Versions before and including 11.25.1
Threats:
An attacker could exploit this vulnerability by conducting Cross-site scripting (XSS) attack .
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: