Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10196

Опубликовано: 05 апр. 2018
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

Отчет

This issue did not affect the versions of nodejs as shipped with Red Hat Enterprise Linux 8 as they already include the patched code. This issue did not affect the versions of rh-nodejs10-nodejs as shipped with Red Hat Software Collections 3 as they already include the patched code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejs:10/nodejsNot affected
Red Hat Mobile Application Platform 4nodejs-http-proxy-agentOut of support scope
Red Hat Software Collectionsrh-nodejs10-npmNot affected
Red Hat Software Collectionsrh-nodejs8-npmWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1567245nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization

EPSS

Процентиль: 58%
0.00364
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

CVSS3: 9.8
github
около 4 лет назад

Resource Exhaustion Denial of Service in http-proxy-agent

EPSS

Процентиль: 58%
0.00364
Низкий

7.3 High

CVSS3