Описание
Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages
The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-25891
- https://github.com/containrrr/shoutrrr/issues/240
- https://github.com/containrrr/shoutrrr/pull/242
- https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42
- https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0
- https://pkg.go.dev/vuln/GO-2022-0528
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059
Пакеты
Наименование
github.com/containrrr/shoutrrr
go
Затронутые версииВерсия исправления
< 0.6.0
0.6.0
Связанные уязвимости
CVSS3: 7.5
nvd
больше 3 лет назад
The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.