PT-2024-28723 · Unknown · Red Discord Bot

Flame442

+1

·

Published

2024-07-11

·

Updated

2024-07-11

·

CVE-2024-39905

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Red-DiscordBot versions prior to 3.5.10
Description A bug in Red's Core API may authorize a user to run a command even when that user doesn't have permissions to manage a channel. This issue affects 3rd-party cogs using the @commands.can manage channel() command permission check without additional permission controls. None of the core commands or core cogs are affected. The maintainers of the project are not aware of any public 3rd-party cog utilizing this API at the time of writing this advisory.
Recommendations For versions prior to 3.5.10, update to version 3.5.10 to resolve the issue. As a temporary workaround, consider unloading any cog using the @commands.can manage channel() command permission check until an upgrade to a patched version can be performed.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-39905
GHSA-5JQ8-Q6RJ-9GQ4

Affected Products

Red Discord Bot