Proxygen fails to validate that a secondary auth manager...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 6, 2025
Description
Published by the National Vulnerability Database
Dec 31, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
May 6, 2025
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.
References