#VU56397 Code Injection in pac-resolver - CVE-2021-23406
Published: September 8, 2021
pac-resolver
Nathan Rajlich
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation within unsafe PAC file handling. A remote attacker can send a specially crafted HTTP request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://github.com/TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bf7a58b3fc64ff9e
- https://github.com/TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04c7d27c13b833f2d5
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506
- https://github.com/TooTallNate/node-pac-resolver/releases/tag/5.0.0
- https://snyk.io/vuln/SNYK-JS-PACRESOLVER-1564857