SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of v9 before v9.26.7 is affected. Other versions (e.g. v8) are not affected. Users should upgrade to version 9.26.7 to receive a patch. A workaround would be to create a command permission overwrite in the Database. A SQL statement provided in the GitHub Security Advisor can be executed to create a overwrite that disallows users without `ManageGuild` permission to run the `-config` command. Run the SQL statement for every server the bot is in, and replace `<guild_id>` with the appropriate Guild ID each time.
Metrics
Affected Vendors & Products
References
History
Sat, 07 Sep 2024 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Onesoftnet
Onesoftnet sudobot |
|
CPEs | cpe:2.3:a:onesoftnet:sudobot:*:*:*:*:*:*:*:* | |
Vendors & Products |
Onesoftnet
Onesoftnet sudobot |
Tue, 03 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 03 Sep 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of v9 before v9.26.7 is affected. Other versions (e.g. v8) are not affected. Users should upgrade to version 9.26.7 to receive a patch. A workaround would be to create a command permission overwrite in the Database. A SQL statement provided in the GitHub Security Advisor can be executed to create a overwrite that disallows users without `ManageGuild` permission to run the `-config` command. Run the SQL statement for every server the bot is in, and replace `<guild_id>` with the appropriate Guild ID each time. | |
Title | SudoBot missing authorization check in `-config` command | |
Weaknesses | CWE-285 CWE-862 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-03T19:01:11.231Z
Updated: 2024-09-03T19:31:25.397Z
Reserved: 2024-08-26T18:25:35.443Z
Link: CVE-2024-45307
Vulnrichment
Updated: 2024-09-03T19:31:22.430Z
NVD
Status : Analyzed
Published: 2024-09-03T19:15:15.033
Modified: 2024-09-07T01:34:05.907
Link: CVE-2024-45307
Redhat
No data.