npm Updates
2555Warning Date
Severity Level
Warning Number
Target Sector
26 January, 2021
● Critical
2021-2373
All
Description:
npm has released security updates to address several vulnerabilities in the following products:
- an0n-chat-lib
- 0.1.04
- 0.1.14
- 0.1.24
- 0.1.34
- 0.1.44
- 0.1.5
- discord-fix
- 0.0.14
- 0.0.2
- sonatype
- 2.0.34
- 2.0.44
- 2.0.54
- 2.0.64
- 2.0.7
Threats:
An attacker could exploit these vulnerabilities by executing arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates: