CVE-2022-23604
A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users who share the same server.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderation. A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users who share the same server. If a bot owner shares the same server as the attacker, it is possible for the attacker to issue bot-owner restricted commands. The issue has been patched in version 1.10.0. One may unload the Defender cog as a workaround.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- x26-cogs project/x26-cogs
- Source
- security-advisories@github.com
References
- https://github.com/Twentysix26/x26-Cogs/commit/72dd9323cb4c90f3a5accac7087605375d178246Patch, Third Party Advisory
- https://github.com/Twentysix26/x26-Cogs/releases/tag/v1.10Release Notes, Third Party Advisory
- https://github.com/Twentysix26/x26-Cogs/security/advisories/GHSA-cfh8-v56j-5757Issue Tracking, Third Party Advisory
- https://github.com/Twentysix26/x26-Cogs/commit/72dd9323cb4c90f3a5accac7087605375d178246Patch, Third Party Advisory
- https://github.com/Twentysix26/x26-Cogs/releases/tag/v1.10Release Notes, Third Party Advisory
- https://github.com/Twentysix26/x26-Cogs/security/advisories/GHSA-cfh8-v56j-5757Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.