CVE-2018-3739 Vulnerability Details
/
/
/
CVE-2018-3739 Metadata Quick Info
CVE Published: 07/06/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2018
Source: hackerone |
Vendor: HackerOne |
Product: https-proxy-agent node module
Status : PUBLISHED
CVE-2018-3739 Description
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the \'auth\' parameter (e.g. JSON).
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-400
CWE Name: Denial of Service (CWE-400)
Source: HackerOne
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).