Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39202

Опубликовано: 13 сент. 2022
Источник: nvd
CVSS3: 4.3
CVSS3: 6.3
EPSS Низкий

Описание

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc perform parsing of such modes incorrectly, potentially resulting in the wrong user being given permissions. Mode commands can only be executed by privileged users, so this can only be abused if an operator is tricked into running the command on behalf of an attacker. The vulnerability has been patched in matrix-appservice-irc 0.35.0. As a workaround users should refrain from entering mode commands suggested by untrusted users. Avoid using multiple modes in a single command.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:*
Версия до 0.35.0 (исключая)

EPSS

Процентиль: 50%
0.00268
Низкий

4.3 Medium

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-269
CWE-269

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

matrix-appservice-irc vulnerable to IRC mode parameter confusion

EPSS

Процентиль: 50%
0.00268
Низкий

4.3 Medium

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-269
CWE-269