SB2022072144 - Denial of service in shoutrrr
Published: July 21, 2022 Updated: November 21, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Resource management error (CVE-ID: CVE-2022-25891)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the util package. A remote attacker can send exactly 2000, 4000, or 6000 characters messages to the application and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://github.com/containrrr/shoutrrr/pull/242
- https://github.com/containrrr/shoutrrr/issues/240
- https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42
- https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059