296,746
Total vulnerabilities in the database
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.
| Software | From | Fixed in |
|---|---|---|
| npmjs / npm | - | 6.14.6 |
| opensuse / leap | 15.1 | 15.1.x |
| opensuse / leap | 15.2 | 15.2.x |
| fedoraproject / fedora | 33 | 33.x |
npm
|
- | 6.14.6 |