PT-2022-16923 · Unknown · Discatsharp
Saalvage
·
Published
2022-04-14
·
Updated
2022-04-22
·
CVE-2022-24849
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DisCatSharp versions 9.8.5 through 9.9.0
DisCatSharp versions prior to 9.9.1 and prior 10.0.0 prereleases
Description
DisCatSharp is a Discord API wrapper for .NET. Users of affected versions who have used either one of the two
RequireDisCatSharpDeveloperAttributes or the BaseDiscordClient.LibraryDeveloperTeam have potentially had their bot token sent to a web server not affiliated with Discord. This server is owned and operated by DisCatSharp's development team. The tokens were not logged, yet it is still advisable to reset the tokens of potentially affected bots.Recommendations
For versions 9.8.5 through 9.9.0, update to version 9.9.1 or later to patch the issue.
For prior 10.0.0 prereleases, update to the latest 10.0.0 prerelease to patch the issue.
As a temporary workaround, consider removing all uses of the two
RequireDisCatSharpDeveloperAttributes and all direct calls to BaseDiscordClient.LibraryDeveloperTeam until a patch is available.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discatsharp