Information Exposure Affecting npm package, versions *


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.24% (63rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1604-NPM-271439
  • published2 Jul 2016
  • disclosed2 Jul 2016

Introduced: 2 Jul 2016

CVE-2016-3956  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

There is no fixed version for Ubuntu:16.04 npm.

NVD Description

Note: Versions mentioned in the description apply only to the upstream npm package and not the npm package as distributed by Ubuntu. See How to fix? for Ubuntu:16.04 relevant fixed versions and status.

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

CVSS Scores

version 3.1