Vulnerability Details CVE-2018-6343
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-6343
-
cpe:2.3:a:facebook:proxygen:2018.10.29.00
-
cpe:2.3:a:facebook:proxygen:2018.11.05.00
-
cpe:2.3:a:facebook:proxygen:2018.11.12.00