Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIzYzctNjQ0NC0zOTlt
Improper Input Validation in sopel-plugins.channelmgnt
Impact
On some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple users at once.
We also believe it may have been possible to remove users from other channels but due to the wonder that is IRC and following RfCs, We have no POC for that.
Freenode is not affected.
Patches
Upgrade to 2.0.1 or higher
Workarounds
Do not use this plugin on networks where TARGMAX > 1.
For more information
If you have any questions or comments about this advisory:
- Open an issue on phab.
- Email us at staff(at)mirahezebots(dot)org
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIzYzctNjQ0NC0zOTlt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 3 years ago
Updated: over 1 year ago
CVSS Score: 7.6
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H
Identifiers: GHSA-23c7-6444-399m, CVE-2021-21431
References:
- https://github.com/MirahezeBots/sopel-channelmgnt/security/advisories/GHSA-23c7-6444-399m
- https://pypi.org/project/sopel-plugins.channelmgnt/
- https://github.com/MirahezeBots/sopel-channelmgnt/commit/7c96d400358221e59135f0a0be0744f3fad73856
- https://nvd.nist.gov/vuln/detail/CVE-2021-21431
- https://github.com/MirahezeBots/sopel-channelmgnt/commit/643388365f28c5cc682254ab913c401f0e53260a
- https://github.com/advisories/GHSA-23c7-6444-399m
Blast Radius: 0.0
Affected Packages
pypi:sopel-plugins.channelmgnt
Dependent packages: 0Dependent repositories: 1
Downloads: 142 last month
Affected Version Ranges: < 2.0.1
Fixed in: 2.0.1
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6
All unaffected versions: 2.0.1, 2.0.2, 2.1.0, 2.1.1, 2.1.2