9
CVSSv2

CVE-2019-10196

Published: 19/03/2021 Updated: 25/03/2021
CVSS v2 Base Score: 9 | Impact Score: 8.5 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 801
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Summary

A flaw was found in http-proxy-agent, prior to version 2.1.0. It exists http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

http-proxy-agent project http-proxy-agent

fedoraproject fedora 27

redhat software collections -

redhat enterprise linux 7.0