CVE-2021-23406

This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pac-resolver_project:pac-resolver:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 05:51

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 8.1
References () https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bf7a58b3fc64ff9e - Patch, Third Party Advisory () https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bf7a58b3fc64ff9e - Patch, Third Party Advisory
References () https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04c7d27c13b833f2d5 - Patch, Third Party Advisory () https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04c7d27c13b833f2d5 - Patch, Third Party Advisory
References () https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0 - Patch, Release Notes, Third Party Advisory () https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0 - Patch, Release Notes, Third Party Advisory
References () https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506 - Exploit, Patch, Third Party Advisory () https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506 - Exploit, Patch, Third Party Advisory
References () https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857 - Exploit, Patch, Third Party Advisory () https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857 - Exploit, Patch, Third Party Advisory

30 Aug 2021, 19:15

Type Values Removed Values Added
References (MISC) https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857 - (MISC) https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857 - Exploit, Patch, Third Party Advisory
References (MISC) https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bf7a58b3fc64ff9e - (MISC) https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bf7a58b3fc64ff9e - Patch, Third Party Advisory
References (MISC) https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506 - (MISC) https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506 - Exploit, Patch, Third Party Advisory
References (MISC) https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0 - (MISC) https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0 - Patch, Release Notes, Third Party Advisory
References (MISC) https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04c7d27c13b833f2d5 - (MISC) https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04c7d27c13b833f2d5 - Patch, Third Party Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:pac-resolver_project:pac-resolver:*:*:*:*:*:node.js:*:*

24 Aug 2021, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-24 08:15

Updated : 2024-11-21 05:51


NVD link : CVE-2021-23406

Mitre link : CVE-2021-23406

CVE.ORG link : CVE-2021-23406


JSON object : View

Products Affected

pac-resolver_project

  • pac-resolver