6.5

CVE-2024-21624

Potential Information Leak in User-Constructed Message Templates in nonebot2

nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to a potential information leak (e.g., environment variables) in instances where developers utilize `MessageTemplate` and incorporate user-provided data into templates. The identified vulnerability has been remedied in pull request #2509 and will be included in versions released from 2.2.0. Users are strongly advised to upgrade to these patched versions to safeguard against the vulnerability. A temporary workaround involves filtering underscores before incorporating user input into the message template.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nonebot ≫ Nonebot Version >= 2.0.1 < 2.2.0
Nonebot ≫ Nonebot Version 2.0.0 Update -
Nonebot ≫ Nonebot Version 2.0.0 Update alpha16
Nonebot ≫ Nonebot Version 2.0.0 Update beta1
Nonebot ≫ Nonebot Version 2.0.0 Update beta2
Nonebot ≫ Nonebot Version 2.0.0 Update beta3
Nonebot ≫ Nonebot Version 2.0.0 Update beta4
Nonebot ≫ Nonebot Version 2.0.0 Update beta5
Nonebot ≫ Nonebot Version 2.0.0 Update rc1
Nonebot ≫ Nonebot Version 2.0.0 Update rc2
Nonebot ≫ Nonebot Version 2.0.0 Update rc3
Nonebot ≫ Nonebot Version 2.0.0 Update rc4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.383
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
security-advisories@github.com 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/nonebot/nonebot2/pull/2509
Patch
Issue Tracking
https://github.com/nonebot/nonebot2/security/advisories/GHSA-59j8-776v-xxxg
Vendor Advisory