CVE-2024-39905

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39905
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-39905.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-39905
Aliases
Related
Published
2024-07-11T16:15:05Z
Modified
2025-01-08T16:15:21.158104Z
Summary
[none]
Details

Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the @commands.can_manage_channel() command permission check without additional permission controls may authorize a user to run a command even when that user doesn't have permissions to manage a channel. None of the core commands or core cogs are affected. The maintainers of the project are not aware of any public 3rd-party cog utilizing this API at the time of writing this advisory. The problem was patched and released in version 3.5.10.

References

Affected packages

Git / github.com/cog-creators/red-discordbot

Affected ranges

Type
GIT
Repo
https://github.com/cog-creators/red-discordbot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

3.*

3.0.0
3.0.0b10
3.0.0b11
3.0.0b12
3.0.0b13
3.0.0b14
3.0.0b15
3.0.0b16
3.0.0b17
3.0.0b17.post1
3.0.0b18
3.0.0b19
3.0.0b20
3.0.0b21
3.0.0b8
3.0.0b8-1
3.0.0b9
3.0.0rc1
3.0.0rc1.post1
3.0.0rc2
3.0.0rc3
3.0.0rc3.post1
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.10
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.12
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9