PT-2023-10275 · Unknown · Zarthus Irc Twitter Announcer Bot

Zarthus

·

Publicado

2023-03-20

·

Atualizado

2024-05-17

·

CVE-2015-10096

CVSS v2.0

4.6

Média

VetorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zarthus IRC Twitter Announcer Bot versions up to 1.1.0
Description A critical issue was found in the Zarthus IRC Twitter Announcer Bot, affecting the get tweets function of the file lib/twitterbot/plugins/twitter announcer.rb. The manipulation of the tweet argument leads to command injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high, and the exploitability is difficult.
Recommendations For Zarthus IRC Twitter Announcer Bot versions up to 1.1.0, upgrade to version 1.1.1 to address this issue. As a temporary workaround, consider restricting access to the get tweets function until the patch is applied.

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-10096

Produtos afetados

Zarthus Irc Twitter Announcer Bot