npm Alert
2848Warning Date
Severity Level
Warning Number
Target Sector
18 September, 2022
● High
2022-5252
All
npm has released a security update to address a vulnerability in the following product:
- parse-server
- < 4.10.14
- >= 5.0.0, < 5.2.5
- nodebb
- <= 1.17.1
Attacker could exploit this vulnerability by doing the following:
- Bypass of a protection mechanism
- Execute arbitrary code
The CERT team encourages users to review npm security advisory and apply the necessary updates: