GHSA-jmqm-f2gx-4fjv
UNKNOWNAffected versions of npm-registry-fetch are vulnerable to an information exposure vulnerability through log files. The cli supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.
- Affected
- >=0, <4.0.5, >=5.0.0, <8.1.1
- Fixed in
- not stated
- Weakness
- CWE-352
- Published
- 2020-07-07
- Source
- osv