CVE-2016-3956

HIGHCVSS 7.5/10EPSS 6.75%

Last modified

CVE-2016-3956 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.. EPSS estimates a 6.75% chance of exploitation in the next 30 days.

Description

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

Metrics

EPSS Probability
6.75%

93.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
IbmSdk<= 1.1.0.20—
IbmSdk<= 1.2.0.10—
IbmSdk<= 4.4.1.0—
NodejsNode.Js0.10.0—
NodejsNode.Js0.10.1—
NodejsNode.Js0.10.2—
NodejsNode.Js0.10.3—
NodejsNode.Js0.10.4—
NodejsNode.Js0.10.5—
NodejsNode.Js0.10.6—
NodejsNode.Js0.10.7—
NodejsNode.Js0.10.8—
NodejsNode.Js0.10.9—
NodejsNode.Js0.10.10—
NodejsNode.Js0.10.11—
NodejsNode.Js0.10.12—
NodejsNode.Js0.10.13—
NodejsNode.Js0.10.14—
NodejsNode.Js0.10.15—
NodejsNode.Js0.10.16—
NodejsNode.Js0.10.16-isaacs-manual—
NodejsNode.Js0.10.17—
NodejsNode.Js0.10.18—
NodejsNode.Js0.10.19—
NodejsNode.Js0.10.20—
NodejsNode.Js0.10.21—
NodejsNode.Js0.10.22—
NodejsNode.Js0.10.23—
NodejsNode.Js0.10.24—
NodejsNode.Js0.10.25—
NodejsNode.Js0.10.26—
NodejsNode.Js0.10.27—
NodejsNode.Js0.10.28—
NodejsNode.Js0.10.29—
NodejsNode.Js0.10.30—
NodejsNode.Js0.10.31—
NodejsNode.Js0.10.32—
NodejsNode.Js0.10.33—
NodejsNode.Js0.10.34—
NodejsNode.Js0.10.35—
NodejsNode.Js0.10.36—
NodejsNode.Js0.10.37—
NodejsNode.Js0.10.38—
NodejsNode.Js0.10.39—
NodejsNode.Js0.10.40—
NodejsNode.Js0.10.41—
NodejsNode.Js0.12.0—
NodejsNode.Js0.12.1—
NodejsNode.Js0.12.2—
NodejsNode.Js0.12.3—

Showing 50 of 89 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-3956?
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
How severe is CVE-2016-3956?
CVE-2016-3956 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 6.75% probability of exploitation in the next 30 days.
How do I fix CVE-2016-3956?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2016

Are you affected by CVE-2016-3956?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST