Lucene search

K
githubGitHub Advisory DatabaseGHSA-23C7-6444-399M
HistoryApr 09, 2021 - 3:42 p.m.

Improper Input Validation in sopel-plugins.channelmgnt

2021-04-0915:42:40
CWE-20
CWE-284
GitHub Advisory Database
github.com
43
input validation
sopel-plugins.channelmgnt
irc servers
kick restrictions
patch 2.0.1
targmax

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H

EPSS

0.001

Percentile

48.0%

Impact

On some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple users at once.
We also believe it may have been possible to remove users from other channels but due to the wonder that is IRC and following RfCs, We have no POC for that.

Freenode is not affected.

Patches

Upgrade to 2.0.1 or higher

Workarounds

Do not use this plugin on networks where TARGMAX > 1.

For more information

If you have any questions or comments about this advisory:

Affected configurations

Vulners
Node
sopel-plugins.channelmgntRange<2.0.1
VendorProductVersionCPE
*sopel-plugins.channelmgnt*cpe:2.3:a:*:sopel-plugins.channelmgnt:*:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H

EPSS

0.001

Percentile

48.0%

Related for GHSA-23C7-6444-399M