CVE Database
/

CVE-2018-3739

Back to search

CVE-2018-3739

Published: Jun 7, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).

VendorProductVersions

HackerOne

https-proxy-agent node module

affected
Versions before 2.1.1

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now