CVE-2024-52505
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 147
Summary
CVE-2024-52505 is a vulnerability affecting the matrix-appservice-irc Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of versions 3.0.0 and 3.0.1 is susceptible to arbitrary IRC command execution, allowing attackers to manipulate the bridge IRC bot. This issue has been rectified in the latest version 3.0.3.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.