Executive brief
https-proxy-agent is a Node.js library used to establish HTTPS connections through a proxy server. Versions before 2.2.0 are vulnerable to denial of service attacks due to improper handling of the proxy.auth parameter, which can be exploited by an attacker to crash the application or consume excessive resources.
Technical details
The vulnerability exists in https-proxy-agent versions prior to 2.2.0 due to unsafe use of the deprecated Buffer constructor. The proxy.auth parameter is passed directly to new Buffer() without sanitization, triggering out-of-bounds read/write behavior (CWE-125, CWE-400). An attacker can supply crafted proxy authentication credentials to trigger a denial of service condition. This is a network-accessible vulnerability requiring no authentication or user interaction. The fix involves replacing new Buffer(proxy.auth) with the safe Buffer.from(proxy.auth) constructor, which properly validates input.
Affected products
- TooTallNate https-proxy-agent < 2.2.0
Timeline
- 2018-07-27: disclosed
- 2018-07-27: patched: Version 2.2.0 released with Buffer.from() fix