Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52rh-5rpj-c3w6

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper handling of multiline messages in node-irc

node-irc is a socket wrapper for the IRC protocol that extends Node.js' EventEmitter. The vulnerability allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. Incorrect handling of a CR character allowed for making part of the message be sent to the IRC server verbatim rather than as a message to the channel. The vulnerability has been patched in node-irc version 1.2.1.

Пакеты

Наименование

matrix-org-irc

npm
Затронутые версииВерсия исправления

<= 1.2.0

1.2.1