{"id":"GHSA-9j49-mfvp-vmhm","summary":"Code Injection in pac-resolver","details":"This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.","aliases":["CVE-2021-23406"],"modified":"2025-01-14T09:12:24.964432Z","published":"2021-09-02T17:10:06Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-08-25T19:28:31Z","nvd_published_at":"2021-08-24T08:15:00Z","cwe_ids":["CWE-94"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23406"},{"type":"WEB","url":"https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bf7a58b3fc64ff9e"},{"type":"WEB","url":"https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04c7d27c13b833f2d5"},{"type":"WEB","url":"https://github.com/TooTallNate"},{"type":"WEB","url":"https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857"}],"affected":[{"package":{"name":"pac-resolver","ecosystem":"npm","purl":"pkg:npm/pac-resolver"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-9j49-mfvp-vmhm/GHSA-9j49-mfvp-vmhm.json"}},{"package":{"name":"degenerator","ecosystem":"npm","purl":"pkg:npm/degenerator"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-9j49-mfvp-vmhm/GHSA-9j49-mfvp-vmhm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}