CVE-2021-23406

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/08/2021
Last modified:
30/08/2021

Description

This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pac-resolver_project:pac-resolver:*:*:*:*:*:node.js:*:* 5.0.0 (excluding)