CVE-2024-45307
Last modified
CVE-2024-45307 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of v9 before v9.26.7 is affected. Other versions (e.g. v8) are not affected. Users should upgrade to version 9.26.7 to receive a patch. A workaround would be to create a command permission overwrite in the Database. A SQL statement provided in the GitHub Security Advisor can be executed to create a overwrite that disallows users without `ManageGuild` permission to run the `-config` command. Run the SQL statement for every server the bot is in, and replace `<guild_id>` with the appropriate Guild ID each time.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Onesoftnet | Sudobot | >= 9.0.0, < 9.26.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45307?
How severe is CVE-2024-45307?
How do I fix CVE-2024-45307?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45301Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In …5.3
- CVE-2024-45302RestSharp is a Simple REST and HTTP API Client for .NET. The…7.8
- CVE-2024-45303Discourse Calendar plugin adds the ability to create a dynam…6.1
- CVE-2024-45304Cairo-Contracts are OpenZeppelin Contracts written in Cairo …6.5
- CVE-2024-45305gix-path is a crate of the gitoxide project dealing with git…2.5
- CVE-2024-45306Vim is an open source, command line text editor. Patch v9.1.…5.5
- CVE-2024-45308HedgeDoc is an open source, real-time, collaborative, markdo…6.5
- CVE-2024-45309OneDev is a Git server with CI/CD, kanban, and packages. A v…7.5
- CVE-2024-4531The Business Card WordPress plugin through 1.0.0 does not ha…7.1
- CVE-2024-45310runc is a CLI tool for spawning and running containers accor…3.6
- CVE-2024-45311Quinn is a pure-Rust, async-compatible implementation of the…7.5
- CVE-2024-45312Overleaf is a web-based collaborative LaTeX editor. Overleaf…5.3
Are you affected by CVE-2024-45307?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
