HIGH7.5
GHSA-477v-w82m-634j
Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages
Quick fix
GHSA-477v-w82m-634j — github.com/containrrr/shoutrrr: upgrade to the fixed version with the command below.
go get github.com/containrrr/shoutrrr@v0.6.0Details
The package `github.com/containrrr/shoutrrr/pkg/util` before 0.6.0 are vulnerable to Denial of Service (DoS) via the `util.PartitionMessage` function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/containrrr/shoutrrr
Introduced in:
0Fixed in: 0.6.0Fix
go get github.com/containrrr/shoutrrr@v0.6.0References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25891[ADVISORY]
- https://github.com/containrrr/shoutrrr/issues/240[WEB]
- https://github.com/containrrr/shoutrrr/pull/242[WEB]
- https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42[WEB]
- https://github.com/containrrr/shoutrrr[PACKAGE]
- https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0[WEB]
- https://pkg.go.dev/vuln/GO-2022-0528[WEB]
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059[WEB]