CRITICAL9.1
GHSA-8g7p-74h8-hg48
Denial of Service in https-proxy-agent
Quick fix
GHSA-8g7p-74h8-hg48 — https-proxy-agent: upgrade to the fixed version with the command below.
npm install https-proxy-agent@2.2.0Details
Versions of `https-proxy-agent` before 2.2.0 are vulnerable to denial of service. This is due to unsanitized options (proxy.auth) being passed to `Buffer()`.
## Recommendation
Update to version 2.2.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3736[ADVISORY]
- https://github.com/TooTallNate/node-https-proxy-agent/commit/1c24219df87524e6ed973127e81f30801d658f07[WEB]
- https://hackerone.com/reports/319532[WEB]
- https://github.com/TooTallNate/node-https-proxy-agent[PACKAGE]
- https://github.com/advisories/GHSA-8g7p-74h8-hg48[ADVISORY]
- https://www.npmjs.com/advisories/593[WEB]