PT-2020-21436 · Hewlett Packard · Https-Proxy-Agent

Published

2020-04-16

·

Updated

2020-04-16

CVSS v3.1

6.1

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions https-proxy-agent versions prior to 2.2.3
Description The issue allows an attacker with access to the proxy server to intercept unencrypted communications, which may include sensitive information such as credentials, by failing to enforce TLS on the socket if the proxy server responds to the request with a HTTP status different than 200.
Recommendations Upgrade to version 2.2.3 or 3.0.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-PC5P-H8PF-MVWP

Affected Products

Https-Proxy-Agent