npm Updates
2533Warning Date
Severity Level
Warning Number
Target Sector
21 September, 2021
● Critical
2021-3548
All
Description:
npm has released a security update to address a vulnerability in the following products:
- mpath
- pac-resolver
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
- Code Injection
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: