CVE-2023-2968
🟡 Monitoruj
Atak zdalny na socket.remoteAddress powoduje błąd typu i może prowadzić do odmowy usługi.
CVSS
7.5
EPSS
1.5%
Exploit
poc
Vendor
proxy_project
Opis źródłowy (NVD)
A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.5% |
| Opublikowano (NVD) | 2023-05-30 18:15:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 18:14:52 UTC |
Referencje
- https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 ([email protected]) [Exploit, Third Party Advisory]