npm Alert
2764Warning Date
Severity Level
Warning Number
Target Sector
23 March, 2022
● Medium
2022-4550
All
npm has released security updates to address several vulnerabilities in the following products:
- faker (npm)
- <= 6.6.6
- electron (npm)
- < 13.6.6
- >= 14.0.0-beta.1, < 14.2.4
- >= 15.0.0-beta.1, < 15.3.5
- >= 16.0.0-beta.1, < 16.0.6
- >= 17.0.0-alpha.1, <= 17.0.0-alpha.5
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
The CERT team encourages users to review npm security advisory and apply the necessary updates: