npm Alert
5751Warning Date
Severity Level
Warning Number
Target Sector
20 July, 2022
● Critical
2022-5042
All
npm has released security updates to address a vulnerability in the following product:
- Java Melody
- net.bull.javamelody:javamelody-core (Maven) Affected versions < 1.61.0
Attacker could exploit this vulnerability by doing the following:
- Cross-site scripting (XSS)
The CERT team encourages users to review npm security advisory and apply the necessary updates: