漏洞标题
矩阵-appservice-irc irc PgDataStore.ts SQL注入
漏洞描述信息
matrix-appservice-irc PgDataStore.ts SQL注入
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
matrix-appservice-irc PgDataStore.ts sql injection
漏洞描述信息
A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version 0.36.0 is able to address this issue. The name of the patch is 179313a37f06b298150edba3e2b0e5a73c1415e7. It is recommended to upgrade the affected component. VDB-213550 is the identifier assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
对消息或数据结构的处理不恰当
漏洞标题
matrix-appservice-irc 安全漏洞
漏洞描述信息
matrix-appservice-irc是Matrix的一款网桥。这个网桥会将所有 IRC 消息传递给 Matrix,并将所有 Matrix 消息传递给 IRC。 matrix-appservice-irc 0.35.1及之前版本存在安全漏洞,该漏洞源于文件src/datastore/postgres/PgDataStore.ts中的未知代码受到影响,对参数roomIds的操作会导致sql注入。
CVSS信息
N/A
漏洞类别
其他