Use-After-Free Vulnerability in Proxygen by Facebook
CVE-2020-1897

9.8CRITICAL

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
18 May 2020

What is CVE-2020-1897?

A use-after-free vulnerability exists in Proxygen due to improper lifetime management in the request adaptor. This flaw can be exploited when a malicious client triggers request error handling in a specific sequence, potentially allowing for unauthorized actions. This issue impacts versions of Proxygen released before May 18, 2020, highlighting the importance of promptly updating to mitigate security risks.

Affected Version(s)

proxygen < unspecified

proxygen v2020.05.18.00

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.