Products
Tinyproxy
- 1.11.1
Source
talos-cna@cisco.com
Tags
CVE-2023-40533 details
Published : May 1, 2024, 4:15 p.m.
Last Modified : May 1, 2024, 7:50 p.m.
Last Modified : May 1, 2024, 7:50 p.m.
Description
An uninitialized memory use vulnerability exists in Tinyproxy 1.11.1 while parsing HTTP requests. In certain configurations, a specially crafted HTTP request can result in disclosure of data allocated on the heap, which could contain sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
CVSS Score
1 | 2 | 3 | 4 | 5.9 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
CVSS Data
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Base Score
5.9
Exploitability Score
Impact Score
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
References
URL | Source |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1902 | talos-cna@cisco.com |
This website uses the NVD API, but is not approved or certified by it.