npm Updates
2477Warning Date
Severity Level
Warning Number
Target Sector
16 March, 2020
● Medium
2020-1024
All
Description:
npm has released security updates to address vulnerabilities in the following versions:
- 5.5.0
- 5.5.1
- 5.5.2
- 5.5.3
- 5.6.0
- 5.6.1
- 5.6.2
- 5.7.0
- 5.7.1
- 5.7.2
- 5.7.3
- 6.0.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.5
- 6.0.6
- 6.0.7
- 6.1.0
- 6.1.1
- 6.2.0
- 6.2.1
- 6.3.0
- 7.0.0
- 7.1.0
- 6.4.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Bypass the type checking validation.
- Denial of Service (DoS).
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: