CVE-2020-15095

MEDIUM

npm CLI <6.14.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.

References (8)

Core 8
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00015.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202101-07

Scores

CVSS v3 4.4
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (5)
fedoraproject/fedora 33
npm/npm 0 - 6.14.6npm
npmjs/npm < 6.14.6
opensuse/leap 15.1
opensuse/leap 15.2
Published Jul 07, 2020
Tracked Since Feb 18, 2026