npm Updates
2648Warning Date
Severity Level
Warning Number
Target Sector
1 December, 2021
● Critical
2021-3955
All
Description:
npm has released security alerts to address multiple vulnerabilities in the following product:
- nodebb
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS)
- Bypass security restrictions
- Path Traversal attack
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory: