CVE-2020-15095
07.07.2020, 19:15
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| npmjs | npm | 𝑥 < 6.14.6 |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| nodejs10 |
| ||||||||||
| nodejs10-devel |
| ||||||||||
| nodejs10-docs |
| ||||||||||
| nodejs12 |
| ||||||||||
| nodejs12-devel |
| ||||||||||
| nodejs12-docs |
| ||||||||||
| nodejs8 |
| ||||||||||
| nodejs8-devel |
| ||||||||||
| nodejs8-docs |
| ||||||||||
| npm10 |
| ||||||||||
| npm12 |
| ||||||||||
| npm8 |
|
Common Weakness Enumeration
References