A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.
The product does not handle or incorrectly handles when a value is not defined or supported for the associated parameter, field, or argument name.
Link | Tags |
---|---|
https://research.jfrog.com/vulnerabilities/undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917 | third party advisory exploit |