PT-2024-28723 · Unknown · Red Discord Bot
Flame442
+1
·
Published
2024-07-11
·
Updated
2024-07-11
·
CVE-2024-39905
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Red-DiscordBot versions prior to 3.5.10
Description
A bug in Red's Core API may authorize a user to run a command even when that user doesn't have permissions to manage a channel. This issue affects 3rd-party cogs using the
@commands.can manage channel() command permission check without additional permission controls. None of the core commands or core cogs are affected. The maintainers of the project are not aware of any public 3rd-party cog utilizing this API at the time of writing this advisory.Recommendations
For versions prior to 3.5.10, update to version 3.5.10 to resolve the issue.
As a temporary workaround, consider unloading any cog using the
@commands.can manage channel() command permission check until an upgrade to a patched version can be performed.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Discord Bot