Lucene search

K
osvGoogleOSV:CVE-2018-3739
HistoryJun 07, 2018 - 2:29 a.m.

CVE-2018-3739

2018-06-0702:29:08
Google
osv.dev
5

9.3 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.7%

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the ‘auth’ parameter (e.g. JSON).

9.3 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.7%