GHSA-pc5p-h8pf-mvwp
UNKNOWNVersions of https-proxy-agent prior to 2.2.3 are vulnerable to Machine-In-The-Middle. The package fails to enforce TLS on the socket if the proxy server responds the to the request with a HTTP status different than 200. This allows an attacker with access to the proxy server to intercept unencrypted communications, which may include sensitive information such as credentials.
- Affected
- >=0, <2.2.3
- Fixed in
- not stated
- Weakness
- CWE-300
- Published
- 2020-04-16
- Source
- osv