Total vulnerabilities in the database
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.
Software | From | Fixed in |
---|---|---|
npmjs / npm | - | 6.14.6 |
opensuse / leap | 15.1 | 15.1.x |
opensuse / leap | 15.2 | 15.2.x |
fedoraproject / fedora | 33 | 33.x |
![]() |
- | 6.14.6 |