Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86wf-436m-h424

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Resource Exhaustion Denial of Service in http-proxy-agent

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

Пакеты

Наименование

http-proxy-agent

npm
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

EPSS

Процентиль: 58%
0.00364
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 7.3
redhat
почти 8 лет назад

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

CVSS3: 9.8
nvd
почти 5 лет назад

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

EPSS

Процентиль: 58%
0.00364
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-665