npm Updates
2526Warning Date
Severity Level
Warning Number
Target Sector
23 February, 2021
● Critical
2021-2512
All
Description:
npm has released security updates to address several vulnerabilities in the following products:
- dynamoose
- fastify-csrf
- @graphql-tools/git-loader
- node-red-dashboard
- async-git
- electron
- @ckeditor/ckeditor5-markdown-gfm
- angular-expressions
- uap-core
- dotty
- total.js
- slashify
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Command injection
- Denial of service attack (DoS)
- Execute arbitrary code –remotely
- Cross-site request forgery (CSRF)
- Path traversal attack
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary updates:
- https://www.npmjs.com/advisories/1610
- https://www.npmjs.com/advisories/1611
- https://www.npmjs.com/advisories/1612
- https://www.npmjs.com/advisories/1613
- https://www.npmjs.com/advisories/1614
- https://www.npmjs.com/advisories/1615
- https://www.npmjs.com/advisories/1616
- https://www.npmjs.com/advisories/1617
- https://www.npmjs.com/advisories/1618
- https://www.npmjs.com/advisories/1619
- https://www.npmjs.com/advisories/1620
- https://www.npmjs.com/advisories/1621
- https://www.npmjs.com/advisories/1622