Information Exposure Affecting npm package, versions <5.8.0+ds-2


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.24% (62nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-NPM-1555386
  • published2 Jul 2016
  • disclosed2 Jul 2016

Introduced: 2 Jul 2016

CVE-2016-3956  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade Debian:12 npm to version 5.8.0+ds-2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream npm package and not the npm package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

CVSS Scores

version 3.1