Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xh2-74w9-5vxm

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Integer overflow in github.com/gorilla/websocket

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

Пакеты

Наименование

github.com/gorilla/websocket

go
Затронутые версииВерсия исправления

< 1.4.1

1.4.1

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-190
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
redhat
больше 6 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
nvd
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
debian
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket ...

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-190
CWE-400