GHSA-jmqm-f2gx-4fjv
MODERATEAffected versions of npm-registry-fetch are vulnerable to an information exposure vulnerability through log files. The cli supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.
- Affected
- >= 5.0.0, < 8.1.1, < 4.0.5
- Fixed in
- 8.1.1
- Weakness
- CWE-352
- Published
- 2020-07-07
- Source
- github