QID 981196
QID 981196: Nodejs (npm) Security Update for https-proxy-agent (GHSA-8g7p-74h8-hg48)
Versions of `https-proxy-agent` before 2.2.0 are vulnerable to denial of service. This is due to unsanitized options (proxy.auth) being passed to `Buffer()`.
## Recommendation
Update to version 2.2.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8g7p-74h8-hg48 for updates pertaining to this vulnerability.
Vendor References
- GHSA-8g7p-74h8-hg48 -
github.com/advisories/GHSA-8g7p-74h8-hg48
CVEs related to QID 981196
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8g7p-74h8-hg48 | https-proxy-agent |
|