VDB
Sign up
MEDIUM6.1

GHSA-pc5p-h8pf-mvwp

Machine-In-The-Middle in https-proxy-agent

Quick fix

GHSA-pc5p-h8pf-mvwp — https-proxy-agent: upgrade to the fixed version with the command below.

npm install https-proxy-agent@2.2.3

Details

Versions of `https-proxy-agent` prior to 2.2.3 are vulnerable to Machine-In-The-Middle. The package fails to enforce TLS on the socket if the proxy server responds the to the request with a HTTP status different than 200. This allows an attacker with access to the proxy server to intercept unencrypted communications, which may include sensitive information such as credentials.

## Recommendation

Upgrade to version 3.0.0 or 2.2.3.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/https-proxy-agent
Introduced in: 0Fixed in: 2.2.3
Fixnpm install https-proxy-agent@2.2.3

References