GHSA-qpgc-xh7j-52q8
Dashboard / Vulnerabilities / GHSA-qpgc-xh7j-52q8
Summary: node-opcua DoS vulnerability via message with memory allocation that exceeds v8's memory limit
Details: The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-25231, https://github.com/node-opcua/node-opcua/pull/1182, https://github.com/node-opcua/node-opcua/commit/7b5044b3f5866fbedc3efabd05e407352c07bd2f, https://github.com/node-opcua/node-opcua, https://security.snyk.io/vuln/SNYK-JS-NODEOPCUA-2988724
Affected packages
Package
Name: node-opcua
Purl: pkg:npm/node-opcua
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -2.74.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
