npm Alert
2543Warning Date
Severity Level
Warning Number
Target Sector
19 June, 2022
● High
2022-4968
All
Description:
npm has released a security update to address a vulnerability in the following products:
- parse-server
- < 4.10.11
- >= 5.0.0, < 5.2.2
- @finastra/nestjs-proxy
- < 0.7.0
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Authentication bypass
- Unauthorized disclosure of information
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: