CVE-2023-2968

A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:proxy_project:proxy:2.0.0:*:*:*:*:node.js:*:*
cpe:2.3:a:proxy_project:proxy:2.1.1:*:*:*:*:node.js:*:*

History

21 Nov 2024, 07:59

Type Values Removed Values Added
References () https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 - Exploit, Third Party Advisory () https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 - Exploit, Third Party Advisory

06 Jun 2023, 14:38

Type Values Removed Values Added
References (MISC) https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 - (MISC) https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:proxy_project:proxy:2.1.1:*:*:*:*:node.js:*:*
cpe:2.3:a:proxy_project:proxy:2.0.0:*:*:*:*:node.js:*:*

30 May 2023, 18:52

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-30 18:15

Updated : 2024-11-21 07:59


NVD link : CVE-2023-2968

Mitre link : CVE-2023-2968

CVE.ORG link : CVE-2023-2968


JSON object : View

Products Affected

proxy_project

  • proxy
CWE
CWE-232

Improper Handling of Undefined Values

NVD-CWE-noinfo