Description
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
Remediation
References
https://github.com/node-opcua/node-opcua/commit/3fd46ec156e7718a506be41f3916310b6bdd0407
https://github.com/node-opcua/node-opcua/commit/7b5044b3f5866fbedc3efabd05e407352c07bd2f
https://github.com/node-opcua/node-opcua/pull/1182
https://security.snyk.io/vuln/SNYK-JS-NODEOPCUA-2988725
Related Vulnerabilities
CVE-2022-43484 Vulnerability in maven package org.terasoluna.gfw:terasoluna-gfw-common
CVE-2020-14966 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2022-45689 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-45394 Vulnerability in maven package org.jenkins-ci.plugins:delete-log-plugin
CVE-2021-40111 Vulnerability in maven package org.apache.james:james-server