vulnerability
SUSE: CVE-2020-15095: SUSE Linux Security Advisory
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 2 | (AV:L/AC:M/Au:N/C:P/I:N/A:N) | Jul 7, 2020 | Oct 3, 2020 | Feb 4, 2022 |
Severity
2
CVSS
(AV:L/AC:M/Au:N/C:P/I:N/A:N)
Published
Jul 7, 2020
Added
Oct 3, 2020
Modified
Feb 4, 2022
Description
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.
Solutions
suse-upgrade-nodejs10suse-upgrade-nodejs10-develsuse-upgrade-nodejs10-docssuse-upgrade-nodejs12suse-upgrade-nodejs12-develsuse-upgrade-nodejs12-docssuse-upgrade-nodejs14suse-upgrade-nodejs14-develsuse-upgrade-nodejs14-docssuse-upgrade-nodejs8suse-upgrade-nodejs8-develsuse-upgrade-nodejs8-docssuse-upgrade-npm10suse-upgrade-npm12suse-upgrade-npm14suse-upgrade-npm8
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.