npm Alert
2469Warning Date
Severity Level
Warning Number
Target Sector
6 March, 2022
● Medium
2022-4478
All
Description:
npm has released security updates to address several vulnerabilities in the following products:
- shescape
- >= 1.4.0, < 1.5.1
- urijs
- < 1.19.9
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Excuate arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: