CVE-2020-15095

MEDIUM4.4EPSS 0.13%

npm CLI exposing sensitive information through logs

Published: 7/7/2020Modified: 3/13/2026
Also known as:GHSA-93f3-23rq-pjfpCGA-cq5c-c68w-493qDEBIAN-CVE-2020-15095

Description

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like `<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>`. The password value is not redacted and is printed to stdout and also to any generated log files.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.4CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

References (10)