ZeroHour

CVE-2018-3739

PoC
CVSS 3.0
9.1 critical
EPSS
2%p80
Published
()
Modified
Description

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).

Vendors
https-proxy-agent project
Products
https-proxy-agent
Weakness
CWE-400, CWE-125
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.