Lucene search

K
osvGoogleOSV:CVE-2021-29466
HistoryApr 22, 2021 - 1:15 a.m.

CVE-2021-29466

2021-04-2201:15:07
Google
osv.dev
3
discord-recon
bot
vulnerability
remote attacker
local files
server
workaround
maintainer
patch
software

AI Score

6.7

Confidence

High

EPSS

0.004

Percentile

74.7%

Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is able to read local files from the server that can disclose important information. As a workaround, a bot maintainer can locate the file app.py and add .replace('..', '') into the Path variable inside of the recon function. The vulnerability is patched in version 0.0.4.

AI Score

6.7

Confidence

High

EPSS

0.004

Percentile

74.7%

Related for OSV:CVE-2021-29466