SB2020101371 - Security restrictions bypass in Channelmgnt plug-in for Sopel
Published: October 13, 2020 Updated: February 4, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2020-15251)
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and take over a channel.
Remediation
Install update from vendor's website.
References
- https://github.com/MirahezeBots/MirahezeBots/security/advisories/GHSA-23pc-4339-95vg
- https://github.com/MirahezeBots/sopel-channelmgnt/pull/3
- https://github.com/MirahezeBots/sopel-channelmgnt/security/advisories/GHSA-j257-jfvv-h3x5
- https://phab.bots.miraheze.wiki/phame/live/1/post/1/summary/
- https://phab.bots.miraheze.wiki/T117
- https://pypi.org/project/sopel-plugins.channelmgnt/