CVE-2018-3739 is a critical vulnerability affecting https-proxy-agent versions prior to 2.1.1. It stems from improper sanitization of the 'auth' option when passed to the Buffer constructor, leading to denial-of-service and uninitialized memory leaks if an attacker can control this input. With a CVSS score of 9.1, this vulnerability is easily exploitable over the network with no user interaction, potentially resulting in high confidentiality impact and denial of service. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.0CPE matchmatch criteria | cpe:2.3:a:https-proxy-agent_project:https-proxy-agent:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.