Description
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).
Remediation
References
https://hackerone.com/reports/319532
Related Vulnerabilities
CVE-2023-49379 Vulnerability in maven package com.jfinal:jfinal
CVE-2019-16728 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify
CVE-2022-25906 Vulnerability in npm package is-http2
CVE-2020-7699 Vulnerability in npm package express-fileupload
CVE-2022-2191 Vulnerability in maven package org.eclipse.jetty:jetty-server