CVE-2021-37696

Source
https://cve.org/CVERecord?id=CVE-2021-37696
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37696.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-37696
Related
  • GHSA-ffhm-9c8j-wx9h
Published
2021-08-11T23:15:07.953Z
Modified
2026-03-13T22:01:07.303237Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access sensitive information by crafting a specific MassDM message. Issue is patched in commit 92325be650a6c17940cc52611797533ed95dbbe1. All users are advised to update to the current commit. As a workaround users may unload the MassDM cog or globally disable the [p]massdm command.

References

Affected packages

Git / github.com/tmercswims/tmerc-cogs

Affected ranges

Type
GIT
Repo
https://github.com/tmercswims/tmerc-cogs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/tmercswims/tmerc-cogs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37696.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "3.0"
            }
        ]
    }
]