HIGH7.5
GHSA-vhfw-v69p-crcw
Uncontrolled Resource Consumption in OPCFoundation.NetStandard.Opc.Ua.Core
Quick fix
GHSA-vhfw-v69p-crcw — OPCFoundation.NetStandard.Opc.Ua.Core: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58Details
A vulnerability was discovered in the OPC UA .NET Standard Stack that allows a malicious client to cause a server to trigger an out of memory exception by sending a large number of message chunks.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua.Core
Introduced in:
0Fixed in: 1.4.368.58Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58References
- https://github.com/OPCFoundation/UA-.NETStandard/security/advisories/GHSA-vhfw-v69p-crcw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-29864[ADVISORY]
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2022-29864.pdf[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard[PACKAGE]