QID 375841
Date Published: 2021-09-23
QID 375841: Node.js Pac-Resolver Module Remote Code Execution (RCE) Vulnerability
The Node.js pac-resolver module could allow a remote attacker to execute arbitrary code on the system, and it occurs when used with untrusted input, due to unsafe PAC file handling
Affected Versions:
pac-resolver before 5.0.0
QID Detection Logic:
This authenticated QID retrieves vulnerable pac-resolver versions by running npm view pac-resolver | grep 'version:'.
An attacker can exploit this issue to execute arbitrary code with in the context of the affected application resulting into Remote Code Execution.
Solution
Customers are advised to upgrade to Node.js pac-resolver 5.0.0 or the latest versions to remediate this vulnerability.
Vendor References
- CVE-2021-23406 -
nvd.nist.gov/vuln/detail/CVE-2021-23406
CVEs related to QID 375841
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-23406 |
|