GMS-2020-414: Sensitive information exposure through logs in npm-registry-fetch
(updated )
Affected versions of npm-registry-fetch
are vulnerable to an information exposure vulnerability through log files. The cli supports URLs like <protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>
. The password value is not redacted and is printed to stdout and also to any generated log files.
References
Detect and mitigate GMS-2020-414 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →