Bug#969163: buster-pu: package npm/5.8.0+ds6-4+deb10u2

2020-08-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2020-08-28 at 14:00 +0200, Xavier Guimard wrote: > npm is vulnerable to CVE-2020-15095: password in URL are stored in > logs. > Please go ahead. Regards, Adam

Bug#969163: buster-pu: package npm/5.8.0+ds6-4+deb10u2

2020-08-28 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, [ Reason ] npm is vulnerable to CVE-2020-15095: password in URL are stored in logs. This fixes import upstream commit to fix it. [ Impact ] (What is the impact for the user if