Skip to content

Security issue in proxy-agent / pac-proxy-agent / pac-resolver #19

@buffcode

Description

@buffcode
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ high          │ Code Injection                                               │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ pac-resolver                                                 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=5.0.0                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ @pm2/agent-node                                              │
│               │ > proxy-agent > pac-proxy-agent > pac-resolver               │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1784                        │
└───────────────┴──────────────────────────────────────────────────────────────┘

All three packages proxy-agent / pac-proxy-agent / pax-resolver need to be updated to >=5.0 in order to mitigate the issue:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions