PT-2022-24803 · Node-Irc+1 · Node-Irc+1

Val Lorentz

·

Published

2022-09-13

·

Updated

2022-09-16

·

CVE-2022-39202

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions matrix-appservice-irc versions prior to 0.35.0
Description The issue arises from a bug in the underlying matrix-org/node-irc library, causing matrix-appservice-irc to incorrectly parse multiple modes in a single mode command. This can potentially result in the wrong user being given permissions. Mode commands can only be executed by privileged users, so exploitation requires an operator to be tricked into running the command on behalf of an attacker.
Recommendations For versions prior to 0.35.0, update to version 0.35.0 to resolve the issue. As a temporary workaround, refrain from entering mode commands suggested by untrusted users. Avoid using multiple modes in a single command until the issue is resolved.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-39202
GHSA-CQ7Q-5C67-W39W

Affected Products

Matrix-Appservice-Irc
Node-Irc