Beveiligingsadvies

CVE-2018-3739

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-06-07 02:00:00
Laatst bijgewerkt 2024-09-17 04:25:44
Toegewezen door hackerone
CVSS-score geen score
Status PUBLISHED

Beschrijving

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).