PT-2023-26555 · Unknown · Matrix-Appservice-Irc
Half-Shot
+1
·
Published
2023-08-04
·
Updated
2023-08-11
·
CVE-2023-38690
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
matrix-appservice-irc versions prior to 1.0.1
Description
The issue allows an attacker to craft a command with newlines that would not be properly parsed, enabling them to pass a string of commands as a channel name, which would then be executed by the IRC bridge bot.
Recommendations
For versions prior to 1.0.1, upgrade to version 1.0.1 or above to resolve the issue.
As a temporary workaround, consider disabling dynamic channels in the config to disable the most common execution method.
Exploit
Fix
Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Matrix-Appservice-Irc