CVE-2021-23406

Published
View on NVD ↗
CVSS v3
8.1
HIGH
CVSS v2
7.5
HIGH
Affected
2
PROJECTS

Description

This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.

Generates an asynchronous resolver function from a PAC file
GitHubGitHub
53
Turns sync functions into async functions
GitHubGitHub
20