← back
CVE-2023-2968highCWE-232

Undefined variable usage in npm package "proxy" leads to remote denial of service

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.5%
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
proxy