Vulnerability Description
This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pac-Resolver Project | Pac-Resolver | < 5.0.0 |
References
- https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bPatchThird Party Advisory
- https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04cPatchThird Party Advisory
- https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0PatchRelease NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857ExploitPatchThird Party Advisory
- https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bPatchThird Party Advisory
- https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04cPatchThird Party Advisory
- https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0PatchRelease NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857ExploitPatchThird Party Advisory
FAQ
What is CVE-2021-23406?
CVE-2021-23406 is a vulnerability with a CVSS score of 8.1 (HIGH). This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-dege...
How severe is CVE-2021-23406?
CVE-2021-23406 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23406?
Check the references section above for vendor advisories and patch information. Affected products include: Pac-Resolver Project Pac-Resolver.