@cyclonedx/cyclonedx-npm is vulnerable to Information Disclosure
10
Low Risk
Affected versions of @cyclonedx/cyclonedx-npm may expose distribution URL credentials in the generated SBOM if they are defined in your package definitions.
You are affected if you are using a vulnerable version of the package and use URL embedded credentials inside your package definitions.
@cyclonedx/cyclonedx-npm is vulnerable to Information Disclosure in versions 1.0.0 - 1.18.0.
Upgrade @cyclonedx/cyclonedx-npm to the patch version (version 1.19.0).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant