---
title: Security Bulletin NR18-06
source: https://docs.newrelic.com/docs/security/new-relic-security/security-bulletins/security-bulletin-nr18-06
---

## Summary

A security update for the Node.js agent corrects an issues where the agent may capture all transaction attributes.

**Release date:** Mar 5, 2018

**Vulnerability identifier:** NR18-06

**Priority:** High

## Affected software [#affected]

The following New Relic agent versions are affected:

| Name          | Affected version                                                                                                                                                                                                             | Notes | Remediated version                                                                             |
| ------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- | ---------------------------------------------------------------------------------------------- |
| Node.js agent | [2.8.0](https://docs.newrelic.com/docs/release-notes/agent-release-notes/nodejs-release-notes/node-agent-280), [2.9.0](https://docs.newrelic.com/docs/release-notes/agent-release-notes/nodejs-release-notes/node-agent-290) |       | [2.9.1](https://docs.newrelic.com/docs/release-notes/agent-release-notes/nodejs-release-notes) |

## Vulnerability information [#vuln-info]

The agent may capture all transaction attributes, even with High-security mode enabled on the account. This may include sensitive data attached to that transaction.

## Workarounds

New Relic has not identified any workarounds for this vulnerability.

## Report security vulnerabilities to New Relic [#report]

New Relic is committed to the security of our customers and their data. If you believe you have found a security vulnerability in one of our products or websites, we welcome and greatly appreciate you reporting it to New Relic's coordinated disclosure program. For more information, see [Reporting security vulnerabilities](https://docs.newrelic.com/docs/security/new-relic-security/data-privacy/reporting-security-vulnerabilities).

## For more help [#more_help]

Additional documentation resources include:.

-   [Upgrade the Node.js agent](https://docs.newrelic.com/docs/agents/nodejs-agent/installation-configuration/upgrade-nodejs-agent)
-   [NR Security](https://newrelic.com/security)
