Home

Description

matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matrix-appservice-irc version 3.0.3.

PUBLISHED Reserved 2024-11-11 | Published 2024-11-14 | Updated 2024-11-14 | Assigner GitHub_M




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-147: Improper Neutralization of Input Terminators

Product status

< 3.0.3
affected

References

github.com/...ce-irc/security/advisories/GHSA-c3hj-hg7p-rrq5

github.com/...ommit/4a024eae1a992b1ea67e71a998e0b833b54221e2

cve.org (CVE-2024-52505)

nvd.nist.gov (CVE-2024-52505)

Download JSON