PT-2021-8866 · Unknown · Https-Proxy-Agent

Laura Pardo

·

Published

2021-03-19

·

Updated

2022-01-06

·

CVE-2019-10196

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions http-proxy-agent versions prior to 2.1.0
Description A flaw was found in http-proxy-agent where it passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the input to the auth parameter to prevent potential exploitation.

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10196
GHSA-86WF-436M-H424

Affected Products

Https-Proxy-Agent