Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
matrix-appservice-irc allows IRC Command injection in provisioning API
Vulnerability Description
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matrix-appservice-irc version 3.0.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
输入终结符转义处理不恰当
Vulnerability Title
matrix-appservice-irc 安全漏洞
Vulnerability Description
matrix-appservice-irc是Matrix的一款网桥。这个网桥会将所有 IRC 消息传递给 Matrix,并将所有 Matrix 消息传递给 IRC。 matrix-appservice-irc 3.0.3之前版本存在安全漏洞。攻击者利用该漏洞可以执行任意 IRC 命令。
CVSS Information
N/A
Vulnerability Type
N/A