Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-php7-7869-j4qf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.

EPSS

Процентиль: 50%
0.00271
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-476

Связанные уязвимости

CVSS3: 7.5
nvd
около 7 лет назад

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.

EPSS

Процентиль: 50%
0.00271
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-476