npm Alert
2562Warning Date
Severity Level
Warning Number
Target Sector
5 June, 2022
● Medium
2022-4911
All
Description:
npm has released a security update to address a vulnerability in the following products:
- gitsome
- <= 0.2.3
- ssl-utils
- <= 1.0.0
- docker-tester
- <= 1.2.1
- formio
- <= 2.0.0
- lifion-verify-deps
- < 1.2.0
- s3-uploader
- <= 2.0.3
- proctree
- <= 0.1.1
- jquery-validation
- < 1.19.4
- google-it
- <= 1.6.2
- markdown-link-extractor
- < 3.0.2
- >= 4.0.0, < 4.0.1
- semver-regex
- < 3.1.4
- >= 4.0.0, < 4.0.3
- devcert
- < 1.2.1
- gatsby-plugin-mdx
- < 2.14.1
- >= 3.0.0, < 3.15.2
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update:
- https://github.com/advisories/GHSA-9v73-x562-wv5x
- https://github.com/advisories/GHSA-552j-pv39-f3jf
- https://github.com/advisories/GHSA-rj88-4777-828h
- https://github.com/advisories/GHSA-52vj-mr2j-f8jh
- https://github.com/advisories/GHSA-rphm-c8gw-3r38
- https://github.com/advisories/GHSA-gwp3-f7mr-qpfv
- https://github.com/advisories/GHSA-cv76-rv4h-4mqc
- https://github.com/advisories/GHSA-j9m2-h2pv-wvph
- https://github.com/advisories/GHSA-7xhv-mpjw-422f
- https://github.com/advisories/GHSA-mmh6-m7v9-5956
- https://github.com/advisories/GHSA-4x5v-gmq8-25ch
- https://github.com/advisories/GHSA-fp36-299x-pwmw
- https://github.com/advisories/GHSA-mj46-r4gr-5x83