Discord Opus Vulnerable to Denial of Service (DoS) Attacks
CVE-2024-21521

7.5HIGH

Key Information:

Vendor

Discord

Vendor
CVE Published:
10 July 2024

What is CVE-2024-21521?

The @discordjs/opus package is vulnerable to a Denial of Service (DoS) attack due to its handling of input objects with a toString property across multiple functions. An attacker could exploit this vulnerability to disrupt the system by causing it to crash, impacting the functionality and availability of applications dependent on this library.

Affected Version(s)

@discordjs/opus 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alessio Della Libera
.