Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIzYzctNjQ0NC0zOTlt

Improper Input Validation in sopel-plugins.channelmgnt

Impact

On some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple users at once.
We also believe it may have been possible to remove users from other channels but due to the wonder that is IRC and following RfCs, We have no POC for that.

Freenode is not affected.

Patches

Upgrade to 2.0.1 or higher

Workarounds

Do not use this plugin on networks where TARGMAX > 1.

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-23c7-6444-399m
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIzYzctNjQ0NC0zOTlt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 3 years ago
Updated: over 1 year ago


CVSS Score: 7.6
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H

Identifiers: GHSA-23c7-6444-399m, CVE-2021-21431
References: Repository: https://github.com/MirahezeBots/sopel-channelmgnt
Blast Radius: 0.0

Affected Packages

pypi:sopel-plugins.channelmgnt
Dependent packages: 0
Dependent repositories: 1
Downloads: 123 last month
Affected Version Ranges: < 2.0.1
Fixed in: 2.0.1
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6
All unaffected versions: 2.0.1, 2.0.2, 2.1.0, 2.1.1, 2.1.2