Lucene search

K
redhatcveRedhat.comRH:CVE-2018-3739
HistoryDec 25, 2019 - 9:27 p.m.

CVE-2018-3739

2019-12-2521:27:53
redhat.com
access.redhat.com
9

0.007 Low

EPSS

Percentile

79.7%

A flaw was found in https-proxy-agent, prior to version 2.2.0. It was discovered https-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

0.007 Low

EPSS

Percentile

79.7%