npm Alert
9216Warning Date
Severity Level
Warning Number
Target Sector
13 October, 2022
● High
2022-5339
All
npm has released security updates to address several vulnerabilities in the following products:
- node-saml
- < 4.0.0-beta.5
- node-saml/node-saml
- < 4.0.0-beta.5
- node-saml/passport-saml
- < 4.0.0- beta.3
- node-saml
- < 4.0.0-beta.5
- passport-saml
- < 3.2.2
Attacker could exploit these vulnerabilities by executing arbitrary code.
The CERT team encourages users to review npm security advisory and apply the necessary updates: