Executive brief
Undici's ProxyAgent, a library component used to route HTTP requests through a proxy server, fails to verify the remote server's TLS certificate. This allows anyone with network access between the client and destination (ISPs, local network users, the proxy itself) to intercept and modify encrypted HTTPS traffic that should be protected, effectively removing all encryption security.
Technical details
The vulnerability is a certificate validation bypass (CWE-295) in Undici's ProxyAgent class. When routing HTTPS requests through an HTTP proxy, the component does not verify the remote server's TLS certificate and always exposes request/response data to the proxy. Additionally, if the proxy URL itself uses HTTP (not HTTPS), nominally HTTPS requests are sent in plaintext over HTTP to the proxy server. This affects versions 4.8.2 through 5.5.0 and is exploitable by any network-adjacent attacker with access to the path between the client and target. The vulnerability was patched in v5.5.1, and the only workaround is to avoid using ProxyAgent for TLS connections.
Affected products
- Node.js Undici 4.8.2 to 5.5.0
Timeline
- 2022-06-17: disclosed
- 2022-06-17: patched: patched in v5.5.1