Lucene search

K
osvGoogleOSV:GHSA-37HR-348P-RMF4
HistoryMay 23, 2022 - 8:17 p.m.

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

2022-05-2320:17:07
Google
osv.dev
4

0.002 Low

EPSS

Percentile

60.6%

matrix-appservice-irc provides an IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc 0.33.2. In terms of a workaround, users should refrain from replying to messages from untrusted participants in IRC-bridged Matrix rooms.

CPENameOperatorVersion
matrix-appservice-irclt0.33.2

0.002 Low

EPSS

Percentile

60.6%

Related for OSV:GHSA-37HR-348P-RMF4