All errata/p9/ALT-PU-2020-2925-2
ALT-PU-2020-2925-2

Package update npm in branch p9

Version6.14.8-alt1
Published2026-02-04
Max severityMEDIUM
Severity:

Closed issues (2)

CVE-2020-15095
MEDIUM4.4

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and also to any generated log files.

Published: 2020-07-07Modified: 2024-11-21
CVSS 2.0LOW 1.9
CVSS:2.0/AV:L/AC:M/Au:N/C:P/I:N/A:N
CVSS 3.xMEDIUM 4.4
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N