Vulnerabilities/

Memory Exposure in tunnel-agent

Severity:
Medium

Description

Versions of tunnel-agent before 0.6.0 are vulnerable to memory exposure.

This is exploitable if user supplied input is provided to the auth value and is a number.

Recommendation

Update the tunnel-agent package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tunnel-agent
Anything's wrong? Let us know Last updated on January 09, 2023