CVE-2023-2968

A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:proxy_project:proxy:2.1.1:*:*:*:*:node.js:*:*
cpe:2.3:a:proxy_project:proxy:2.0.0:*:*:*:*:node.js:*:*

History

06 Jun 2023, 14:38

Type Values Removed Values Added
References (MISC) https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 - (MISC) https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:proxy_project:proxy:2.0.0:*:*:*:*:node.js:*:*
cpe:2.3:a:proxy_project:proxy:2.1.1:*:*:*:*:node.js:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Proxy Project proxy
Proxy Project

30 May 2023, 18:52

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-30 18:15

Updated : 2023-06-06 14:38


NVD link : CVE-2023-2968

Mitre link : CVE-2023-2968


JSON object : View

Products Affected

proxy_project

  • proxy