Privilege escalation in Defender
Published Feb 15, 2022
8.8
HIGHCVSS 3.1
EPSS 1.13%
Description
x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderation. A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users who share the same server. If a bot owner shares the same server as the attacker, it is possible for the attacker to issue bot-owner restricted commands. The issue has been patched in version 1.10.0. One may unload the Defender cog as a workaround.
Affected products
-
- Version < 1.10.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Twentysix26 | x26-Cogs | n/a |
|
- < 1.10.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28574 Advisory
- https://github.com/Twentysix26/x26-Cogs/commit/72dd9323cb4c90f3a5accac7087605375d178246 x_refsource_MISCPatchThird Party Advisory
- https://github.com/Twentysix26/x26-Cogs/releases/tag/v1.10 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/Twentysix26/x26-Cogs/security/advisories/GHSA-cfh8-v56j-5757 x_refsource_CONFIRMIssue TrackingThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28574 | Advisory | |
| https://github.com/Twentysix26/x26-Cogs/commit/72dd9323cb4c90f3a5accac7087605375d178246 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/Twentysix26/x26-Cogs/releases/tag/v1.10 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/Twentysix26/x26-Cogs/security/advisories/GHSA-cfh8-v56j-5757 | x_refsource_CONFIRMIssue TrackingThird Party Advisory |
Change history (0)
No recorded changes yet.