CVE-2025-27146
- EPSS 0.15%
- Veröffentlicht 25.02.2025 20:15:38
- Zuletzt bearbeitet 04.03.2025 20:42:55
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands exec...
CVE-2023-38700
- EPSS 0.27%
- Veröffentlicht 04.08.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:14:05
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Versi...
CVE-2023-38690
- EPSS 0.13%
- Veröffentlicht 04.08.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:03
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would t...
CVE-2022-3971
- EPSS 0.06%
- Veröffentlicht 13.11.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:20:38
A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql inject...
CVE-2022-39203
- EPSS 0.31%
- Veröffentlicht 13.09.2022 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:17:46
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant them...
CVE-2022-39202
- EPSS 0.27%
- Veröffentlicht 13.09.2022 18:15:15
- Zuletzt bearbeitet 21.11.2024 07:17:46
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions...
CVE-2022-29166
- EPSS 0.85%
- Veröffentlicht 05.05.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:58:37
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patch...