Skip to content

Incorrect permissions on all admin related commands

High
parker02311 published GHSA-3rx8-6453-7q26 Apr 7, 2024

Package

No package listed

Affected versions

<=1.0.1

Patched versions

1.0.2

Description

Impact

All hubs before V1.0.2 are impacted. All commands on these versions are capable of being ran by all users including admin commands, this allows users to:

  • Receive products for free
  • Delete/create/update products/tags/etc

The only non-affected command is /products admin clear as this was already programmed for bot owners only.

Patches

All users should upgrade to V1.0.2 ASAP, there are no breaking changes.

Workarounds

It will be easier to just upgrade as there is no breaking changes from V1 to V1.0.2

For more information

You can ask any further questions on our Discord server or via email

Severity

High

CVE ID

CVE-2024-31442

Weaknesses

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files. Learn more on MITRE.

Credits