npm Alert
2648Warning Date
Severity Level
Warning Number
Target Sector
12 June, 2022
● Critical
2022-4937
All
Description:
npm has released a security update to address a vulnerability in the following products:
- metacal
- < 0.0.2
- semantic-release
- >= 17.0.4, < 19.0.3
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: