Vulnerabilities > CVE-2022-40468 - Insecure Default Initialization of Resource vulnerability in Tinyproxy Project Tinyproxy

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tinyproxy-project
CWE-1188

Summary

Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.