CVE Vulnerabilities

CVE-2020-15095

Insertion of Sensitive Information into Log File

Published: Jul 07, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.4 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like ://[[:]@][:][:][/]. The password value is not redacted and is printed to stdout and also to any generated log files.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
NpmNpmjs*6.14.6 (excluding)
Red Hat Enterprise Linux 8RedHatnodejs:12-8020020201007080935.4cda2c84*
Red Hat Enterprise Linux 8RedHatnodejs:10-8030020210118191659.229f0a1c*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatnodejs:12-8010020201006223055.c27ad7f8*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-nodejs12-nodejs-0:12.18.4-3.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-nodejs10-nodejs-0:10.23.1-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-nodejs12-nodejs-0:12.18.4-3.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-nodejs10-nodejs-0:10.23.1-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-nodejs12-nodejs-0:12.18.4-3.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-nodejs10-nodejs-0:10.23.1-2.el7*
NpmUbuntubionic*
NpmUbuntueoan*
NpmUbuntufocal*
NpmUbuntutrusty*
NpmUbuntutrusty/esm*
NpmUbuntuxenial*

Potential Mitigations

References