npm Updates
2364Warning Date
Severity Level
Warning Number
Target Sector
10 November, 2020
● Critical
2020-2028
All
Description:
npm has released security updates to address multiple vulnerabilities in the following products:
- scratch-svg-renderer
- 0.1.0 0.2.0-prerelease.20180605154326
- 0.2.0-prerelease.20180607141644
- 0.2.0-prerelease.20180613184320
- 0.2.0-prerelease.20180618172917
- 0.2.0-prerelease.20180711180400
- 0.2.0-prerelease.20180712223402
- 0.2.0-prerelease.20180817005452
- 0.2.0-prerelease.20180821210632
- 0.2.0-prerelease.20180907141232
- 0.2.0-prerelease.20180926143036
- 0.2.0-prerelease.20181017193458
- 0.2.0-prerelease.20181024192149
- 0.2.0-prerelease.20181101210634
- 0.2.0-prerelease.20181126212715
- 0.2.0-prerelease.20181212190400
- 0.2.0-prerelease.20181212222326
- 0.2.0-prerelease.20181212230607
- 0.2.0-prerelease.20181213165142
- 0.2.0-prerelease.20181213192400
- 0.2.0-prerelease.20181218153528
- 0.2.0-prerelease.20181220183040
- 0.2.0-prerelease.20190109201344
- 0.2.0-prerelease.20190110205335
- 0.2.0-prerelease.20190125192231
- 0.2.0-prerelease.20190304180800
- 0.2.0-prerelease.20190329052730
- 0.2.0-prerelease.20190419183947
- 0.2.0-prerelease.20190521170426
- 0.2.0-prerelease.20190523193400
- 0.2.0-prerelease.20190715144718
- 0.2.0-prerelease.20190715153806
- 0.2.0-prerelease.20190820171249
- 0.2.0-prerelease.20190822193232
- 0.2.0-prerelease.20190822202608
- 0.2.0-prerelease.20191031221353
- 0.2.0-prerelease.20191104164753
- 0.2.0-prerelease.20191217211338
- 0.2.0-prerelease.20200103191258
- 0.2.0-prerelease.20200103211543
- 0.2.0-prerelease.20200109070519
- 0.2.0-prerelease.20200205003215
- 0.2.0-prerelease.20200205003400
- 0.2.0-prerelease.20200507183648
- 0.2.0-prerelease.20200604203226
- 0.2.0-prerelease.20200609210443
- 0.2.0-prerelease.20200610220938
- 0.2.0-prerelease.20201008203328
- 0.2.0-prerelease.20201009194722
- 0.2.0-prerelease.20201009195807
- 0.2.0-prerelease.20201009202925
- 0.2.0-prerelease.20201009211507
- 0.2.0-prerelease.20201011114003
- 0.2.0-prerelease.20201012151417
- 0.2.0-prerelease.20201013123302
- 0.2.0-prerelease.20201013184332
- 0.2.0-prerelease.20201014105708
- 0.2.0-prerelease.20201014130133
- 0.2.0-prerelease.20201014145347
- 0.2.0-prerelease.20201015122106
- 0.2.0-prerelease.20201015135047
- 0.2.0-prerelease.20201015194358
- 0.2.0-prerelease.20201016121710
- discord.dll
- 1.0.0
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Executing arbitrary code
- Code Injection
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: