npm Alert
2406Warning Date
Severity Level
Warning Number
Target Sector
10 October, 2022
● High
2022-5321
All
npm has released security updates to address several vulnerabilities in the following products:
- generator-jhipster
- > 6.8.0, < 6.9.0
- tiny-csrf
- < 1.1.0
- v8n
- < 1.5.1
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Execute arbitrary code
The CERT team encourages users to review npm security advisory and apply the necessary updates: