MEDIUM5.3
GHSA-mw9h-hcp7-fgc6
Exposure of Sensitive Information in OPCFoundation.NetStandard.Opc.Ua.Server
Quick fix
GHSA-mw9h-hcp7-fgc6 — OPCFoundation.NetStandard.Opc.Ua.Server: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Server --version 1.4.370.9Details
OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua.Server
Introduced in:
0Fixed in: 1.4.370.9Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Server --version 1.4.370.9References
- https://nvd.nist.gov/vuln/detail/CVE-2022-33916[ADVISORY]
- https://github.com/OPCFoundation/UA-.NETStandard/commit/313aa2a2499d8690cf719a67176e131517bb8b78[WEB]
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2022-33916.pdf[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard[PACKAGE]