Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38690


matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge bot. Versions 1.0.1 and above are patched. There are no robust workarounds to the bug. One may disable dynamic channels in the config to disable the most common execution method but others may exist.


Published

2023-08-04T17:15:10.783

Last Modified

2024-11-21T08:14:03.810

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application matrix matrix_irc_bridge < 1.0.1 Yes

References