CVE-2020-15095
Aliases:GHSA-93f3-23rq-pjfpDEBIAN-CVE-2020-15095CGA-gmq6-85cf-hf77CGA-jr76-83m4-vw38CGA-m3rh-w895-8w36CGA-pxv6-6vx6-hcvhCGA-26c3-g4w5-59gxCGA-288w-72r9-rm44CGA-2933-6mxh-wxjhCGA-2mvc-pv4p-25mfCGA-2q2j-6349-wx35CGA-36fc-jh4r-cm98CGA-37xv-j666-6qwgCGA-385g-cmjc-g89wCGA-3fgx-j9c8-8257CGA-3jgp-3xfj-rp46CGA-3m3v-v2w4-fpj7CGA-3pmh-v5wc-865pCGA-3rxw-xqjq-2c8jCGA-3vrw-2gj3-r854CGA-3x5j-7wwv-36j4CGA-47wj-v28r-4crfCGA-4cm6-xvmw-gp36CGA-4h96-37xr-5w6hCGA-4m59-qmcm-6p73CGA-4q8f-crv5-5wx5CGA-4qw9-pmq5-2r69CGA-52cv-7p2m-c2j8CGA-5727-9g54-2p98CGA-584v-vhv2-q7x4CGA-5f25-8846-5pfjCGA-5f4x-98f3-f6hxCGA-5f8g-67vx-qrjqCGA-5jf8-mvxw-56j9CGA-5rc6-rmr3-h8g4CGA-5xww-68wc-fv59CGA-6689-qq7p-p5w8CGA-6hjc-g36h-g73jCGA-6qmg-gp5f-8vxrCGA-6wfh-663m-xh9hCGA-724g-rqjg-r7jxCGA-758f-5rj9-3mh4CGA-7vrr-mcm4-9pq4CGA-7xjf-vf66-83qrCGA-83p8-266f-ppq5CGA-86jv-7h5f-hwwvCGA-86x7-hxp6-gc4xCGA-8c85-88wj-rq7cCGA-8cff-3xwr-3vxvCGA-8j5h-f9fw-2cg6CGA-8pc3-536x-x32xCGA-8x4q-x58q-mx4gCGA-98wx-r5rg-mxwcCGA-9hc5-j5vc-2f4mCGA-9pcj-f8wf-2cg6CGA-9qv9-f434-vv74CGA-c6qv-xpg9-qr44CGA-c6rx-4wv6-jq87CGA-cf6x-m7j4-wj2mCGA-cgf5-37jr-9c9jCGA-chjm-gpj2-r766CGA-cpc5-qjww-6gwgCGA-cqqj-qxjr-x8gpCGA-cvf2-gq49-mv99CGA-cw9h-vm9h-v7vjCGA-cx6x-fgvg-92qjCGA-f6q5-j7mj-fpwjCGA-f9wc-c4cj-g36vCGA-fgc9-m2q8-fvx7CGA-fmm3-g897-rr3qCGA-fvgp-4hj7-hcxhCGA-fwp7-jvh4-xr5cCGA-fxvv-8m39-v49rCGA-g2wj-rwqv-c9vxCGA-g8cm-pcpj-fmvvCGA-gc9r-v43p-8j7fCGA-grfh-488x-889fCGA-gv72-r7j8-7w54CGA-h587-m9w6-mc38CGA-h5r9-9h9h-3882CGA-h7xf-g4wv-xgqrCGA-h974-4j45-86p8CGA-h9mh-8mp6-jpmwCGA-hc3x-fj84-8925CGA-hj7c-72hg-9f9qCGA-hvq4-9xqq-gv6xCGA-hwm7-r98j-fwrqCGA-j328-78j4-xv3xCGA-j3qj-xwgg-7ff2CGA-j46v-v3cf-qv37CGA-jjq2-25x5-q727CGA-jm73-427q-x86wCGA-jm8c-v8g5-crhrCGA-jqm5-xp5m-2vgrCGA-jr47-q76p-76jxCGA-jr98-r7hc-6h6vCGA-mcrq-h7vm-chpjCGA-mq6c-j2pq-p58mCGA-mq9j-2rvw-pm3vCGA-p3gj-hr2f-vh8qCGA-pp9j-27qp-xrj3CGA-pq6h-4pmx-x746CGA-pqph-h5hh-ffv3CGA-prwm-h5r4-vc3cCGA-q2w7-6qxf-jc9xCGA-q69m-fxgj-2c5vCGA-q6r7-7fgr-rh66CGA-q9j8-7mpq-3cpwCGA-qm3m-g7vx-rvv5CGA-qq4p-r2f8-7c2hCGA-qrx5-85v4-7795CGA-qwjx-5v4c-7fm3CGA-qwm3-5vcx-x7f8CGA-qwxp-g9fw-vvrvCGA-rfxv-vg6w-6pr7CGA-rmf9-pj4r-gw8gCGA-rqqp-v487-rhj5CGA-rwjf-44mx-rjv3CGA-v3mw-w977-7hmmCGA-v46w-q664-4r43CGA-v4j3-whv6-q4vqCGA-vfp5-qw4g-cj4gCGA-vvjv-44cv-36fwCGA-w2p2-75v2-x258CGA-wfwh-53vp-ghc9CGA-wh78-4vvj-c857CGA-wmjp-jqcw-5m58CGA-x323-67c9-c5xxCGA-x5ch-jr4q-9g42CGA-x5q3-v67c-fw66CGA-x9pc-hjcr-97gpCGA-xgrh-qg84-g74qCGA-xvcg-2f8m-c588CGA-xx76-gpf4-rj3jCGA-4mw3-2wvw-qj9wCGA-6hj7-j9gg-c7q2CGA-cgxv-gpf6-cq7fCGA-5wff-rrh5-35jvCGA-qwmh-rfqc-c5r2CGA-9hjc-fwmq-7fm3CGA-c875-mvmx-6rqxCGA-h48c-8q45-7fr5CGA-xhf8-m8c4-v5w2CGA-2wx3-ppg7-r52jCGA-9p5c-xmg9-6f9hCGA-qhxh-vwxf-8x25CGA-ghm6-cwxq-7v9g
Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 07 Jul 2020, 18:55
Last modified:04 Aug 2024, 13:08
Vulnerability Summary
Overall Risk (default)
low
18/100 CVSS Score
4.4 MEDIUM
v3.1 (cve.org)
EPSS Score
0.41% LOW
0% probability +0.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
07 Jul 2020, 18:55
Published
Vulnerability first disclosed
04 Aug 2024, 13:08
Last Modified
Vulnerability information updated
Description
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.4CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.41%• Percentile: 35%
Techniques & Countermeasures
- CWE-532•Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
Affected Systems
- chainguard•code-server
< 0
- chainguard•code-server-compat
< 0
- chainguard•commercial-gitlab-rails-ee-assets-19.1
all
- chainguard•commercial-gitlab-rails-ee-assets-19.3
all
- chainguard•commercial-gitlab-rails-ee-assets-fips-19.1
all
- chainguard•commercial-gitlab-rails-ee-assets-fips-19.2
all
- chainguard•commercial-gitlab-rails-ee-assets-fips-19.3
all
- chainguard•gitlab-rails-ce-18.1
< 0
- chainguard•gitlab-rails-ce-18.2
< 0
- chainguard•gitlab-rails-ce-18.3
< 0
- chainguard•gitlab-rails-ce-18.4
< 0
- chainguard•gitlab-rails-ce-18.5
< 0
- chainguard•gitlab-rails-ce-18.6
< 0
- chainguard•gitlab-rails-ce-18.7
< 0
- chainguard•gitlab-rails-ce-assets-18.1
< 0
- chainguard•gitlab-rails-ce-assets-18.10
< 0
- chainguard•gitlab-rails-ce-assets-18.11
< 0
- chainguard•gitlab-rails-ce-assets-18.2
< 0
- chainguard•gitlab-rails-ce-assets-18.3
< 0
- chainguard•gitlab-rails-ce-assets-18.4
< 0
- chainguard•gitlab-rails-ce-assets-18.5
< 0
- chainguard•gitlab-rails-ce-assets-18.6
< 0
- chainguard•gitlab-rails-ce-assets-18.7
< 0
- chainguard•gitlab-rails-ce-assets-18.8
< 0
- chainguard•gitlab-rails-ce-assets-18.9
< 0
- chainguard•gitlab-rails-ce-assets-19.0
< 0
- chainguard•gitlab-rails-ce-assets-19.1
< 0
- chainguard•gitlab-rails-ce-assets-19.2
< 0
- chainguard•gitlab-rails-ce-assets-19.3
< 0
- chainguard•gitlab-rails-ce-assets-19.4
all
- chainguard•gitlab-rails-ce-assets-fips-18.1
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.10
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.11
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.2
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.3
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.4
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.5
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.6
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.7
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.8
< 0
- chainguard•gitlab-rails-ce-assets-fips-18.9
< 0
- chainguard•gitlab-rails-ce-assets-fips-19.0
< 0
- chainguard•gitlab-rails-ce-assets-fips-19.1
< 0
- chainguard•gitlab-rails-ce-assets-fips-19.2
< 0
- chainguard•gitlab-rails-ce-assets-fips-19.3
< 0
- chainguard•gitlab-rails-ce-assets-fips-19.4
all
- chainguard•gitlab-rails-ce-doc-18.1
< 0
- chainguard•gitlab-rails-ce-doc-18.2
< 0
- chainguard•gitlab-rails-ce-doc-18.3
< 0
- chainguard•gitlab-rails-ce-doc-18.4
< 0
Showing first 50 affected entries in server-rendered view.
References (11)
- https://github.com/npm/cli/security/advisories/GHSA-93f3-23rq-pjfp
- https://github.com/npm/cli/commit/a9857b8f6869451ff058789c4631fadfde5bbcbc
- https://github.com/npm/cli/blob/66aab417f836a901f8afb265251f761bb0422463/CHANGELOG.md#6146-2020-07-07
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/
- https://security.gentoo.org/glsa/202101-07
- https://nvd.nist.gov/vuln/detail/CVE-2020-15095
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6
- https://security-tracker.debian.org/tracker/CVE-2020-15095