Skip to content

Sensitive information exposure through logs

Low
claudiahdz published GHSA-jmqm-f2gx-4fjv Jul 7, 2020

Package

npm npm-registry-fetch (npm)

Affected versions

< 4.0.5 || >=5.0.0 <8.1.1

Patched versions

8.1.1, 4.0.5

Description

Affected versions of npm-registry-fetch are vulnerable to an information exposure vulnerability through log files. 

The cli supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs