npm Alert
2770Warning Date
Severity Level
Warning Number
Target Sector
26 June, 2022
● High
2022-4998
All
Description:
npm has released a security update to address a vulnerability in the following products:
- rsshub
- <= 1.0.0
- lettersanitizer
- < 1.0.2
- jsrsasign
- >= 4.8.0, < 10.5.25
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Improper Input Validation
- Denial of service attack (DoS)
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: