CVE-2024-52505

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 147

Summary

CVE-2024-52505 is a vulnerability affecting the matrix-appservice-irc Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of versions 3.0.0 and 3.0.1 is susceptible to arbitrary IRC command execution, allowing attackers to manipulate the bridge IRC bot. This issue has been rectified in the latest version 3.0.3.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share