GHSA-vh4f-fgpp-x8x2

Suggest an improvement
Source
https://github.com/advisories/GHSA-vh4f-fgpp-x8x2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-vh4f-fgpp-x8x2/GHSA-vh4f-fgpp-x8x2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vh4f-fgpp-x8x2
Aliases
Published
2022-08-25T00:00:29Z
Modified
2023-11-08T04:08:30.926023Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
node-opcua DoS when bypassing limitations for excessive memory consumption
Details

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

Database specific
{
    "nvd_published_at": "2022-08-24T05:15:00Z",
    "github_reviewed_at": "2022-09-01T22:23:21Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "HIGH"
}
References

Affected packages

npm / node-opcua

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.0