HIGH
GHSA-6fp8-cxc9-4fr9
Uncontrolled Resource Consumption in OPCFoundation.NetStandard.Opc.Ua.Core
Quick fix
GHSA-6fp8-cxc9-4fr9 — OPCFoundation.NetStandard.Opc.Ua.Core: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58Details
A vulnerability was discovered in the OPC UA .NET Standard Stack that allows a malicious client to trigger a stack overflow exception in a server that exposes an HTTPS endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua.Core
Introduced in:
0Fixed in: 1.4.368.58Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58References
- https://github.com/OPCFoundation/UA-.NETStandard/security/advisories/GHSA-6fp8-cxc9-4fr9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-29866[ADVISORY]
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2022-29866.pdf[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard[PACKAGE]