Skip to content

Sensitive information leak in MassDM

High
tmercswims published GHSA-ffhm-9c8j-wx9h Aug 11, 2021

Package

MassDM (Red-DiscordBot)

Affected versions

c53a2e5566bd5f923939ca1edd10524d40f00a5e

Patched versions

92325be650a6c17940cc52611797533ed95dbbe1

Description

Impact

A vulnerability has been found in the code that allows any user to access sensitive information by crafting a specific MassDM message.

Patches

Issue is patched in commit 92325be.

Workarounds

Unload the MassDM cog or globally disable the [p]massdm command.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-37696

Weaknesses

No CWEs

Credits