Описание
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
Ссылки
- Broken LinkThird Party Advisory
- ExploitThird Party Advisory
- Broken LinkThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:discordjs:opus:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 60%
0.00394
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-908
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Uncontrolled Resource Consumption in @discordjs/opus
EPSS
Процентиль: 60%
0.00394
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-908