The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.
References
Link | Resource |
---|---|
https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42 | Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/issues/240 | Exploit Issue Tracking Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/pull/242 | Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0 | Release Notes Third Party Advisory |
https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059 | Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42 | Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/issues/240 | Exploit Issue Tracking Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/pull/242 | Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0 | Release Notes Third Party Advisory |
https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059 | Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 06:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42 - Patch, Third Party Advisory | |
References | () https://github.com/containrrr/shoutrrr/issues/240 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/containrrr/shoutrrr/pull/242 - Patch, Third Party Advisory | |
References | () https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0 - Release Notes, Third Party Advisory | |
References | () https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059 - Patch, Third Party Advisory |
21 Jul 2022, 14:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:containrrr:shoutrrr:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
References | (CONFIRM) https://github.com/containrrr/shoutrrr/issues/240 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
References | (CONFIRM) https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0 - Release Notes, Third Party Advisory | |
References | (CONFIRM) https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42 - Patch, Third Party Advisory | |
References | (CONFIRM) https://github.com/containrrr/shoutrrr/pull/242 - Patch, Third Party Advisory | |
References | (CONFIRM) https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059 - Patch, Third Party Advisory |
15 Jul 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-07-15 20:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-25891
Mitre link : CVE-2022-25891
CVE.ORG link : CVE-2022-25891
JSON object : View
Products Affected
containrrr
- shoutrrr
CWE