npm Updates
2549Warning Date
Severity Level
Warning Number
Target Sector
4 October, 2020
● Critical
2020-1869
All
Description:
npm has released security updates to address multipule vulnerabilities in the following products:
- electorn
- 10.0.0
- loadyaml
- 1.0.2
- socket.io-file
- 1.0.0 1.0.1 1.0.11 1.0.12 1.0.13 1.0.2 1.0.21 1.0.3 1.0.31 1.0.32 1.0.4 1.0.41 1.0.5 1.0.51 1.0.52 1.0.53 1.0.54 1.0.55 1.0.56 1.0.57 1.0.58 1.0.59 2.0.0 2.0.1 2.0.12 2.0.13 2.0.14 2.0.15 2.0.2 2.0.3 2.0.31
Threats:
- File restriction bypass
- Download a malicious package in electorn and loadyaml.
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: