Vulnerabilities/

Parsing issue in matrix-org/node-irc leading to room takeovers

Severity:
High

Description

Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the channel.

Recommendation

Update the matrix-appservice-irc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-appservice-irc
Anything's wrong? Let us know Last updated on January 29, 2023

This issue is available in SmartScanner Professional

See Pricing