Lucene search

K
cvelistHackeroneCVELIST:CVE-2018-3739
HistoryApr 26, 2018 - 12:00 a.m.

CVE-2018-3739

2018-04-2600:00:00
CWE-400
hackerone
www.cve.org

9.1 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.7%

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the ‘auth’ parameter (e.g. JSON).

CNA Affected

[
  {
    "product": "https-proxy-agent node module",
    "vendor": "HackerOne",
    "versions": [
      {
        "status": "affected",
        "version": "Versions before 2.1.1"
      }
    ]
  }
]

9.1 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.7%

Related for CVELIST:CVE-2018-3739