Lucene search

K
cve[email protected]CVE-2021-29466
HistoryApr 22, 2021 - 1:15 a.m.

CVE-2021-29466

2021-04-2201:15:07
CWE-24
CWE-22
web.nvd.nist.gov
14
discord-recon
file disclosure
remote attacker
security vulnerability
nvd
cve-2021-29466

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%

Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is able to read local files from the server that can disclose important information. As a workaround, a bot maintainer can locate the file app.py and add .replace('..', '') into the Path variable inside of the recon function. The vulnerability is patched in version 0.0.4.

Affected configurations

Vulners
NVD
Node
demon1adiscord-reconRange0.0.3
VendorProductVersionCPE
demon1adiscord\-recon*cpe:2.3:a:demon1a:discord\-recon:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Discord-Recon",
    "vendor": "DEMON1A",
    "versions": [
      {
        "status": "affected",
        "version": "<= 0.0.3"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%

Related for CVE-2021-29466