{"id":"GHSA-pc5p-h8pf-mvwp","summary":"Machine-In-The-Middle in https-proxy-agent","details":"Versions of `https-proxy-agent` prior to 2.2.3 are vulnerable to Machine-In-The-Middle. The package fails to enforce TLS on the socket if the proxy server responds the to the request with a HTTP status different than 200. This allows an attacker with access to the proxy server to intercept unencrypted communications, which may include sensitive information such as credentials.\n\n\n## Recommendation\n\nUpgrade to version 3.0.0 or 2.2.3.","modified":"2023-11-01T20:54:11Z","published":"2020-04-16T03:14:56Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-300"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-04-16T03:03:19Z"},"references":[{"type":"WEB","url":"https://github.com/TooTallNate/node-https-proxy-agent/commit/36d8cf509f877fa44f4404fce57ebaf9410fe51b"},{"type":"WEB","url":"https://hackerone.com/reports/541502"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-HTTPSPROXYAGENT-469131"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1184"}],"affected":[{"package":{"name":"https-proxy-agent","ecosystem":"npm","purl":"pkg:npm/https-proxy-agent"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.2.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-pc5p-h8pf-mvwp/GHSA-pc5p-h8pf-mvwp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}