A new Debian Linux update has been published: DLA 3229-1: node-log4js security update
A node-log4js security update has been released for Debian GNU/Linux 10 LTS to address an issue where default file permissions for log files are world-readable.Read more @ Linux Compatible