Severity: high

Denial of Service

https-proxy-agent

Overview

Versions of https-proxy-agent before 2.2.0 are vulnerable to denial of service. This is due to unsanitized options (proxy.auth) being passed to Buffer().

Remediation

Update to version 2.2.0 or later.

Advisory timeline

  1. published

    Advisory published
    Apr 24th, 2018
  2. reported

    Apr 24th, 2018