VulnerabilityModified
CVE-2020-15095
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files.
MEDIUM 4.4EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- npmjs/npm · opensuse/leap · fedoraproject/fedora
- Source
- security-advisories@github.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.htmlMailing List, Third Party Advisory
- https://github.com/npm/cli/blob/66aab417f836a901f8afb265251f761bb0422463/CHANGELOG.md#6146-2020-07-07Release Notes, Third Party Advisory
- https://github.com/npm/cli/commit/a9857b8f6869451ff058789c4631fadfde5bbcbcPatch, Third Party Advisory
- https://github.com/npm/cli/security/advisories/GHSA-93f3-23rq-pjfpThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.htmlMailing List, Third Party Advisory
- https://github.com/npm/cli/blob/66aab417f836a901f8afb265251f761bb0422463/CHANGELOG.md#6146-2020-07-07Release Notes, Third Party Advisory
- https://github.com/npm/cli/commit/a9857b8f6869451ff058789c4631fadfde5bbcbcPatch, Third Party Advisory
- https://github.com/npm/cli/security/advisories/GHSA-93f3-23rq-pjfpThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.