CVE-2024-35237
Last modified
CVE-2024-35237 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants them roles in a Discord server, and stores information about them in a database backend. A vulnerability that exists prior to commit 48e3e5e7ead6777fa75d57c7711c8e55b501c24e impacts all users who have performed verification with an instance of MIT IdentiBot that meets the following conditions: The instance of IdentiBot is tied to a "public" Discord application—i.e., users other than the API access registrant can add it to servers; *and* the instance has not yet been patched. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants them roles in a Discord server, and stores information about them in a database backend. A vulnerability that exists prior to commit 48e3e5e7ead6777fa75d57c7711c8e55b501c24e impacts all users who have performed verification with an instance of MIT IdentiBot that meets the following conditions: The instance of IdentiBot is tied to a "public" Discord application—i.e., users other than the API access registrant can add it to servers; *and* the instance has not yet been patched. In affected versions, IdentiBot does not check that a server is authorized before allowing members to execute slash and user commands in that server. As a result, any user can join IdentiBot to their server and then use commands (e.g., `/kerbid`) to reveal the full name and other information about a Discord user who has verified their affiliation with MIT using IdentiBot. The latest version of MIT IdentiBot contains a patch for this vulnerability (implemented in commit 48e3e5e7ead6777fa75d57c7711c8e55b501c24e). There is no way to prevent exploitation of the vulnerability without the patch. To prevent exploitation of the vulnerability, all vulnerable instances of IdentiBot should be taken offline until they have been updated.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-35237?
How severe is CVE-2024-35237?
How do I fix CVE-2024-35237?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-35230GeoServer is an open source software server written in Java …5.3
- CVE-2024-35231rack-contrib provides contributed rack middleware and utilit…8.6
- CVE-2024-35232github.com/huandu/facebook is a Go package that fully suppor…3.7
- CVE-2024-35234Discourse is an open-source discussion platform. Prior to ve…6.1
- CVE-2024-35235OpenPrinting CUPS is an open source printing system for Linu…6.7
- CVE-2024-35236Audiobookshelf is a self-hosted audiobook and podcast server…4.8
- CVE-2024-35238Minder by Stacklok is an open source software supply chain s…5.3
- CVE-2024-35239Umbraco Commerce is an open source dotnet web forms solution…5.4
- CVE-2024-3524A vulnerability, which was classified as problematic, has be…5.4
- CVE-2024-35240Umbraco Commerce is an open source dotnet ecommerce solution…5.4
- CVE-2024-35241Composer is a dependency manager for PHP. On the 2.x branch …8.8
- CVE-2024-35242Composer is a dependency manager for PHP. On the 2.x branch …8.8
Are you affected by CVE-2024-35237?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
