Vulnerability in NPM package pac-resolver, which has 3 million downloads per week

A vulnerability (CVE-2021-23406) has been discovered in the NPM package pac-resolver, which has over 3 million downloads per week. This vulnerability allows an attacker to execute their own JavaScript code in the context of an application when sending HTTP requests from Node.js projects that support automatic proxy configuration.

The pac-resolver package parses PAC files that include a script for automatic proxy configuration. A PAC file contains standard JavaScript code with the FindProxyForURL function, which defines the logic for selecting a proxy based on the host and the requested URL. The essence of the vulnerability is that the JavaScript code in pac-resolver was executed using the VM API provided in Node.js, which allows running JavaScript code in a different context of the V8 engine.

This API is explicitly marked in the documentation as unsuitable for running untrusted code, as it does not provide full isolation for the executed code and allows access to the original context. The issue has been fixed in release pac-resolver 5.0.0, which has switched to using the vm2 library, providing a higher level of isolation suitable for running untrusted code.

Vulnerability in NPM package pac-resolver, which has 3 million downloads per week

When using the vulnerable version of pac-resolver, an attacker can execute their own JavaScript code in the context of the code of a project using Node.js by providing a specially crafted PAC file, if this project uses libraries that have pac-resolver as a dependency. The most popular among the problematic libraries is Proxy-Agent, which is specified in the dependencies of 360 projects, including urllib, aws-cdk, mailgun.js, and firebase-tools, which collectively account for over three million downloads per week.

If an application that is dependent on pac-resolver loads a PAC file supplied by a system supporting the WPAD automatic proxy configuration protocol, attackers with access to the local network can exploit the distribution of proxy settings via DHCP to substitute malicious PAC files.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster