Vulnerabilities > CVE-2022-25345 - Use of Uninitialized Resource vulnerability in Discordjs Opus

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
discordjs
CWE-908

Summary

All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.

Vulnerable Configurations

Part Description Count
Application
Discordjs
1

Common Weakness Enumeration (CWE)