GHSA-pc5p-h8pf-mvwp

Suggest an improvement
Source
https://github.com/advisories/GHSA-pc5p-h8pf-mvwp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-pc5p-h8pf-mvwp/GHSA-pc5p-h8pf-mvwp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pc5p-h8pf-mvwp
Downstream
Published
2020-04-16T03:14:56Z
Modified
2023-11-01T20:54:11Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Machine-In-The-Middle in https-proxy-agent
Details

Versions of https-proxy-agent prior to 2.2.3 are vulnerable to Machine-In-The-Middle. The package fails to enforce TLS on the socket if the proxy server responds the to the request with a HTTP status different than 200. This allows an attacker with access to the proxy server to intercept unencrypted communications, which may include sensitive information such as credentials.

Recommendation

Upgrade to version 3.0.0 or 2.2.3.

Database specific
{
    "cwe_ids": [
        "CWE-300"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-04-16T03:03:19Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / https-proxy-agent

Package

Name
https-proxy-agent
View open source insights on deps.dev
Purl
pkg:npm/https-proxy-agent

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-pc5p-h8pf-mvwp/GHSA-pc5p-h8pf-mvwp.json"