UBUNTU-CVE-2016-3956
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-3956
UBUNTU-CVE-2016-3956
Summary:
Details: The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
References: https://ubuntu.com/security/CVE-2016-3956, https://nodejs.org/en/blog/vulnerability/npm-tokens-leak-march-2016/, https://github.com/npm/npm/issues/8380, http://www-01.ibm.com/support/docview.wss?uid=swg21980827, http://blog.npmjs.org/post/142036323955/fixing-a-bearer-token-vulnerability, https://ubuntu.com/security/notices/USN-4785-1, https://www.cve.org/CVERecord?id=CVE-2016-3956
Affected packages
Package
Name: npm
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
