@cyclonedx/cyclonedx-npm is vulnerable to Information Disclosure
10
Low Risk
Affected versions of @cyclonedx/cyclonedx-npm may expose distribution URL credentials in the generated SBOM if they are defined in your package definitions.
You are affected if you are using a vulnerable version of the package and use URL embedded credentials inside your package definitions.
@cyclonedx/cyclonedx-npm is vulnerable to Information Disclosure in versions 1.0.0 - 1.18.0.
Upgrade @cyclonedx/cyclonedx-npm to the patch version (version 1.19.0).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant