npm Alert
12639Warning Date
Severity Level
Warning Number
Target Sector
25 May, 2022
● Medium
2022-4879
All
npm has released a security update to address a vulnerability in the following products:
- auth0-lock
- < 11.33.0
- next-auth
- < 3.29.3
- >= 4.0.0, < 4.3.3
- @chainsafe/lodestar
- < 0.36.0
An attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS)
- Buffer overflow
The CERT team encourages users to review npm security advisory and apply the necessary update: