Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j257-jfvv-h3x5

Опубликовано: 13 окт. 2020
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 7.7

Описание

Privilege Escalation in Channelmgnt plug-in for Sopel

Impact

Malicious users are able to op/voice and take over a channel

Patches

On version 1.0.3

Workarounds

Disable channelmgnt

References

https://phab.bots.miraheze.wiki/T117

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

sopel_plugins.channelmgnt

pip
Затронутые версииВерсия исправления

< 1.0.3

1.0.3

Наименование

sopel-plugins-channelmgnt

pip
Затронутые версииВерсия исправления

< 1.0.3

1.0.3

EPSS

Процентиль: 57%
0.00349
Низкий

6.3 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is an ACL bypass vulnerability. This plugin is bundled with MirahezeBot-Plugins with versions from 9.0.0 and less than 9.0.2 affected. Version 9.0.2 includes 1.0.3 of channelmgnt, and thus is safe from this vulnerability. See referenced GHSA-23pc-4339-95vg.

CVSS3: 7.7
nvd
больше 5 лет назад

In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is an ACL bypass vulnerability. This plugin is bundled with MirahezeBot-Plugins with versions from 9.0.0 and less than 9.0.2 affected. Version 9.0.2 includes 1.0.3 of channelmgnt, and thus is safe from this vulnerability. See referenced GHSA-23pc-4339-95vg.

EPSS

Процентиль: 57%
0.00349
Низкий

6.3 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-862
CWE-863