Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-3739
HistoryJun 07, 2018 - 2:29 a.m.

Design/Logic Flaw

2018-06-0702:29:00
PRIOn knowledge base
www.prio-n.com
3

9 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.7%

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the ‘auth’ parameter (e.g. JSON).

CPENameOperatorVersion
https-proxy-agentlt2.2.0

9 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.7%