PT-2022-16923 · Unknown · Discatsharp

Saalvage

·

Published

2022-04-14

·

Updated

2022-04-22

·

CVE-2022-24849

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DisCatSharp versions 9.8.5 through 9.9.0 DisCatSharp versions prior to 9.9.1 and prior 10.0.0 prereleases
Description DisCatSharp is a Discord API wrapper for .NET. Users of affected versions who have used either one of the two RequireDisCatSharpDeveloperAttributes or the BaseDiscordClient.LibraryDeveloperTeam have potentially had their bot token sent to a web server not affiliated with Discord. This server is owned and operated by DisCatSharp's development team. The tokens were not logged, yet it is still advisable to reset the tokens of potentially affected bots.
Recommendations For versions 9.8.5 through 9.9.0, update to version 9.9.1 or later to patch the issue. For prior 10.0.0 prereleases, update to the latest 10.0.0 prerelease to patch the issue. As a temporary workaround, consider removing all uses of the two RequireDisCatSharpDeveloperAttributes and all direct calls to BaseDiscordClient.LibraryDeveloperTeam until a patch is available.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24849
GHSA-FRXG-HF44-Q765

Affected Products

Discatsharp