Skip to content

Remote code execution in WarnSystem module

High
laggron42 published GHSA-834g-67vv-m9wq May 9, 2021

Package

warnsystem.py (Red-DiscordBot)

Affected versions

<1.3.18

Patched versions

1.3.18

Description

Impact

What kind of vulnerability is it? Who is impacted?

A vulnerability has been found in the code that allows any user to access sensible informations by setting up a specific template.

Patches

Has the problem been patched? What versions should users upgrade to?

The problem has been patched here: c79dd2c

Users should update and type !warnsysteminfo to check that their version is 1.3.18 or above.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Unload the WarnSystem cog or disable the !warnset description command globally.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-29502

Weaknesses

No CWEs

Credits