npm Alert
2440Warning Date
Severity Level
Warning Number
Target Sector
3 March, 2022
● High
2022-4463
All
npm has released security updates to address several vulnerabilities in the following products:
- reveal.js
- < 4.3.0
- fluture-node
- >= 4.0.0, < 4.0.2
- @finastra/ssr-pages
- < 0.1.5
- < 0.1.4
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS)
- Path traversal
The CERT team encourages users to review npm security advisory and apply the necessary updates: