AVG-2554 log

Package npm
Status Fixed
Severity Medium
Type insufficient validation
Affected 8.1.4-1
Fixed 8.4.1-1
Current 10.9.0-1 [extra]
Ticket None
Created Sat Nov 13 19:24:31 2021
Issue Severity Remote Type Description
CVE-2021-43616 Medium Yes Insufficient validation
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from...
References
https://github.com/npm/cli/issues/2701
https://github.com/npm/cli/pull/4363
https://github.com/npm/cli/releases/tag/v8.4.1