CVE-2021-43616

CVE-2021-43616

The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json.

Source: CVE-2021-43616

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다