Critical Vulnerabilities 2021 Incident #59 CVE-2021-23406

PAC-Resolver SSRF/RCE

Estimated Financial Impact
AWS CDK, Firebase CLI affected
Blast Radius
CVSS 8.1; 3M weekly downloads

What Happened

A critical RCE vulnerability (CVSS 8.1) in pac-resolver via unsafe Node.js VM module usage. The package had ~3M weekly downloads and was a transitive dependency of AWS CDK, Firebase CLI, and many enterprise applications via the proxy-agent package.

✓

Risk Guard: Caught

VULN_RECENT_FREQUENCY + maintainer health preconditions

Risk Guard Check Codes That Flag This Incident

VULN_RECENT_FREQUENCY

How Every Tool Performed

1 Caught 0 Partial 5 After damage 0 Missed
Tool Verdict Details
OSS Risk Guard Caught VULN_RECENT_FREQUENCY + maintainer health preconditions
Socket After damage Detects after CVE published
Snyk After damage CVE detection after publication; reactive not proactive
Sonatype (Nexus) After damage Detects after CVE published
Black Duck After damage Detects after CVE published
Endor Labs After damage CVE detection + reachability analysis after publication; reactive
← Lodash prototype pollution node-netmask SSRF →