npm Updates
2515Warning Date
Severity Level
Warning Number
Target Sector
18 October, 2020
● Critical
2020-1935
All
Description:
npm has released security updates to address multiple vulnerabilities in the following products:
- npm-user-validate
- 0.0.1 0.0.2 0.0.3 0.0.4 0.1.0 0.1.1 0.1.2 0.1.3 0.1.4 0.1.5 1.0.0
- nodetest199
- 1.0.0
- nodetest1010
- 1.0.0 1.0.1
- plutov-slack-client
- 1.0.0 1.0.1
- npmpubman
- 1.0.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Dineal of Service (DoS)
- Execute arbitrary code
- Information disclosure
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update:
We also recommend to check the details of the affected products until npm release the necessary update: