发布时间: 2022年7月22日
修改时间: 2024年10月31日
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path> . The password value is not redacted and is printed to stdout and also to any generated log files.
NVD | openEuler | |
---|---|---|
Confidentiality | High | High |
Attack Vector | Local | Local |
CVSS评分 | 4.4 | 4.4 |
Attack Complexity | High | High |
Privileges Required | Low | Low |
Scope | Unchanged | Unchanged |
Integrity | None | None |
User Interaction | Required | Required |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-1666 | nodejs security update | 2022年7月22日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | nodejs | Fixed |
KY3.4-5A | nodejs | Fixed |