log4js Project log4js (log4js-node) 2.5.1 for Node.js

CPE Details

log4js Project log4js (log4js-node) 2.5.1 for Node.js
2.5.1
2022-01-25
16h07 +00:00
2022-01-25
16h26 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:log4js_project:log4js:2.5.1:*:*:*:*:node.js:*:*

Informations

Vendor

log4js_project

Product

log4js

Version

2.5.1

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-21704 2022-01-18 23h00 +00:00 log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.
5.5
Moyen