Description
A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.
Remediation
References
https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917
Related Vulnerabilities
CVE-2021-23353 Vulnerability in maven package org.webjars:jspdf
CVE-2021-4260 Vulnerability in npm package oils
CVE-2020-7656 Vulnerability in npm package jquery
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2022-25647 Vulnerability in maven package com.google.code.gson:gson