- What: A vulnerability in npm allows security bypass
- Impact: Local attackers may exploit this to bypass security controls
[WID-SEC-2024-1076] npm: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 4.4 (mittel) CVSS Temporal Score 3.9 (niedrig) Remoteangriff nein Datum 24.01.2022 Stand UPDATE 01.09.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung npm ist ein Paketmanager für die JavaScript-Laufzeitumgebung Node.js. Produkte UPDATE 31.08.2026 Dell Secure Connect Gateway <5.36.00.16 UPDATE 09.05.2024 SUSE Linux UPDATE 02.03.2022 Avaya Aura Communication Manager Avaya Aura Session Manager Avaya Aura Application Enablement Services Avaya Aura System Manager Avaya Aura Experience Portal UPDATE 01.02.2022 Oracle Linux 24.01.2022 Red Hat Enterprise Linux 8.4 Open Source npm Angriff Angriff Ein lokaler Angreifer kann eine Schwachstelle in npm ausnutzen, um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben