npm Alert
2852Warning Date
Severity Level
Warning Number
Target Sector
1 February, 2022
● High
2022-4304
All
npm has released security updates to address several vulnerabilities in the following products:
- zip-local < 0.3.5
- bmoor < 0.10.1
- keyget <= 2.4.0
Attacker could exploit these vulnerabilities by doing the following:
- Path traversal attack
- Prototype Pollution
The CERT team encourages users to review npm security advisory: