PT-2022-17588 · Shoutrrr · Shoutrrr

Justinsteven

·

Published

2022-07-15

·

Updated

2022-07-30

·

CVE-2022-25891

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions github.com/containrrr/shoutrrr/pkg/util versions prior to 0.6.0
Description The issue is related to a Denial of Service (DoS) that can be triggered via the util.PartitionMessage function by sending messages of exactly 2000, 4000, or 6000 characters in length. This can cause a panic when sending such a message to Discord.
Recommendations For versions prior to 0.6.0, update to version 0.6.0 or later to resolve the issue. As a temporary workaround, consider disabling the util.PartitionMessage function until a patch is available. Avoid sending messages of exactly 2000, 4000, or 6000 characters in length to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-31969
CVE-2022-25891
GHSA-477V-W82M-634J
GO-2022-0528
SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059

Affected Products

Shoutrrr