PT-2023-10275 · Unknown · Zarthus Irc Twitter Announcer Bot
Zarthus
·
Publicado
2023-03-20
·
Atualizado
2024-05-17
·
CVE-2015-10096
CVSS v2.0
4.6
Média
| Vetor | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zarthus IRC Twitter Announcer Bot versions up to 1.1.0
Description
A critical issue was found in the Zarthus IRC Twitter Announcer Bot, affecting the
get tweets function of the file lib/twitterbot/plugins/twitter announcer.rb. The manipulation of the tweet argument leads to command injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high, and the exploitability is difficult.Recommendations
For Zarthus IRC Twitter Announcer Bot versions up to 1.1.0, upgrade to version 1.1.1 to address this issue. As a temporary workaround, consider restricting access to the
get tweets function until the patch is applied.Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zarthus Irc Twitter Announcer Bot