CVE-2018-3739 Vulnerability Details

  /     /     /  

CVE-2018-3739 Metadata Quick Info

CVE Published: 07/06/2018 | CVE Updated: 17/09/2024 | CVE Year: 2018
Source: hackerone | Vendor: HackerOne | Product: https-proxy-agent node module
Status : PUBLISHED

CVE-2018-3739 Description

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the \'auth\' parameter (e.g. JSON).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-400
CWE Name: Denial of Service (CWE-400)
Source: HackerOne

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).