CVE-2024-45307

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2024-45307
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45307.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-45307
Aliases
  • GHSA-crgg-w3rr-r9h4
Published
2024-09-03T19:15:15Z
Modified
2024-09-07T04:45:17.160061Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the -config command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of v9 before v9.26.7 is affected. Other versions (e.g. v8) are not affected. Users should upgrade to version 9.26.7 to receive a patch. A workaround would be to create a command permission overwrite in the Database. A SQL statement provided in the GitHub Security Advisor can be executed to create a overwrite that disallows users without ManageGuild permission to run the -config command. Run the SQL statement for every server the bot is in, and replace <guild_id> with the appropriate Guild ID each time.

References

Affected packages

Git / github.com/onesoft-sudo/sudobot

Affected ranges

Type
GIT
Repo
https://github.com/onesoft-sudo/sudobot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0

v2.*

v2.1.0
v2.2.0
v2.4.0
v2.5.0
v2.6.0-alpha1

v3.*

v3.0.0
v3.0.0-alpha1
v3.0.1
v3.0.2

v4.*

v4.0.0
v4.0.0-alpha
v4.0.0-alpha1
v4.0.0-snapshot1
v4.0.1
v4.0.2
v4.1.0
v4.1.1
v4.1.2
v4.10.0
v4.100.0
v4.101.0
v4.102.0
v4.103.0
v4.104.0
v4.105.0
v4.106.0
v4.107.0
v4.107.1
v4.107.2
v4.108.0
v4.109.0
v4.109.1
v4.11.0
v4.110.0
v4.110.1
v4.111.0
v4.112.0
v4.113.0
v4.114.0
v4.114.1
v4.114.2
v4.115.0
v4.116.0
v4.117.0
v4.118.0
v4.119.0
v4.12.0
v4.12.1
v4.12.2
v4.12.3
v4.120.0
v4.121.0
v4.122.0
v4.123.0
v4.124.0
v4.125.0
v4.126.0
v4.127.0
v4.128.0
v4.129.0
v4.13.0
v4.130.0
v4.131.0
v4.132.0
v4.132.1
v4.133.0
v4.134.0
v4.135.0
v4.14.0
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.17.0
v4.17.1
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.20.0
v4.20.1
v4.21.0
v4.22.0
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.23.4
v4.23.5
v4.24.0
v4.25.0
v4.26.0
v4.26.1
v4.27.0
v4.28.0
v4.28.1
v4.28.2
v4.28.3
v4.28.4
v4.29.0
v4.29.1
v4.29.2
v4.3.0
v4.30.0
v4.30.1
v4.30.2
v4.31.0
v4.32.0
v4.32.1
v4.33.0
v4.34.0
v4.34.1
v4.34.2
v4.34.3
v4.35.0
v4.36.0
v4.36.1
v4.37.0
v4.37.1
v4.38.0
v4.39.0
v4.39.1
v4.4.0
v4.40.0
v4.40.1
v4.40.2
v4.40.3
v4.40.4
v4.41.0
v4.41.1
v4.41.2
v4.42.0
v4.43.0
v4.44.0
v4.45.0
v4.45.1
v4.45.2
v4.45.3
v4.46.0
v4.47.0
v4.47.1
v4.47.2
v4.47.3
v4.47.4
v4.47.5
v4.48.0
v4.49.0
v4.5.0
v4.50.0
v4.51.0
v4.52.0
v4.52.1
v4.53.0
v4.54.0
v4.54.1
v4.54.2
v4.55.0
v4.56.0
v4.56.1
v4.56.2
v4.56.3
v4.57.0
v4.58.0
v4.59.0
v4.59.1
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.60.0
v4.60.1
v4.61.0
v4.62.0
v4.63.0
v4.64.0
v4.65.0
v4.66.0
v4.67.0
v4.68.0
v4.68.1
v4.68.2
v4.69.0
v4.7.0
v4.70.0
v4.70.1
v4.70.2
v4.71.0
v4.72.0
v4.72.1
v4.72.2
v4.72.3
v4.72.4
v4.73.0
v4.73.1
v4.74.0
v4.75.0
v4.76.0
v4.76.1
v4.76.2
v4.77.0
v4.77.1
v4.77.2
v4.78.0
v4.79.0
v4.79.1
v4.8.0
v4.8.1
v4.80.0
v4.81.0
v4.82.0
v4.82.1
v4.82.2
v4.83.0
v4.83.1
v4.83.2
v4.83.3
v4.84.0
v4.84.1
v4.84.2
v4.85.0
v4.85.1
v4.85.2
v4.86.0
v4.87.0
v4.88.0
v4.89.0
v4.9.0
v4.90.0
v4.91.0
v4.92.0
v4.93.0
v4.94.0
v4.95.0
v4.96.0
v4.97.0
v4.98.0
v4.98.1
v4.99.0

v5.*

v5.0.0
v5.1.0
v5.1.1
v5.10.0
v5.11.0
v5.11.1
v5.12.0
v5.12.1
v5.12.2
v5.12.3
v5.13.0
v5.13.1
v5.14.0
v5.15.0
v5.16.0
v5.17.0
v5.17.1
v5.18.0
v5.19.0
v5.19.1
v5.19.2
v5.19.3
v5.2.0
v5.2.1
v5.20.0
v5.20.1
v5.20.2
v5.21.0
v5.21.1
v5.22.0
v5.23.0
v5.24.0
v5.25.0
v5.26.0
v5.27.0
v5.27.1
v5.27.2
v5.28.0
v5.29.0
v5.29.1
v5.29.2
v5.3.0
v5.30.0
v5.30.1
v5.31.0
v5.32.0
v5.32.1
v5.33.0
v5.34.0
v5.35.0
v5.35.1
v5.36.0
v5.37.0
v5.38.0
v5.38.1
v5.39.0
v5.4.0
v5.4.1
v5.40.0
v5.40.1
v5.41.0
v5.41.1
v5.41.2
v5.42.0
v5.43.0
v5.43.1
v5.44.0
v5.44.1
v5.45.0
v5.46.0
v5.46.1
v5.47.0
v5.47.1
v5.48.0
v5.49.0
v5.5.0
v5.5.1
v5.5.2
v5.50.0
v5.51.0
v5.52.0
v5.53.0
v5.53.1
v5.53.2
v5.54.0
v5.55.0
v5.56.0
v5.57.0
v5.58.0
v5.59.0
v5.6.0
v5.60.0
v5.61.0
v5.62.0
v5.62.1
v5.63.0
v5.63.1
v5.63.2
v5.64.0
v5.65.0
v5.66.0
v5.67.0
v5.68.0
v5.69.0
v5.69.1
v5.7.0
v5.70.0
v5.71.0
v5.72.0
v5.72.1
v5.73.0
v5.74.0
v5.74.1
v5.75.0
v5.75.1
v5.76.0
v5.77.0
v5.78.0
v5.78.1
v5.78.2
v5.78.3
v5.78.4
v5.79.0
v5.8.0
v5.80.0
v5.80.1
v5.80.2
v5.80.3
v5.81.0
v5.82.0
v5.82.1
v5.9.0

v6.*

v6.0.0
v6.0.1
v6.0.2
v6.0.3
v6.1.0
v6.1.1
v6.1.2
v6.10.0
v6.11.0
v6.12.0
v6.12.1
v6.12.2
v6.13.0
v6.14.0
v6.15.0
v6.15.1
v6.16.0
v6.16.1
v6.17.0
v6.18.0
v6.18.1
v6.19.0
v6.19.1
v6.19.2
v6.2.0
v6.20.0
v6.20.1
v6.20.2
v6.20.3
v6.20.4
v6.21.0
v6.21.1
v6.22.0
v6.23.0
v6.24.0
v6.25.0
v6.25.1
v6.25.2
v6.26.0
v6.27.0
v6.28.0
v6.29.0
v6.3.0
v6.30.0
v6.31.0
v6.31.1
v6.31.2
v6.32.0
v6.33.0
v6.34.0
v6.34.1
v6.34.2
v6.34.3
v6.35.0
v6.35.1
v6.35.2
v6.35.3
v6.35.4
v6.35.5
v6.35.6
v6.35.7
v6.35.8
v6.36.0
v6.37.0
v6.38.0
v6.39.0
v6.39.1
v6.4.0
v6.4.1
v6.4.2
v6.40.0
v6.41.0
v6.42.0
v6.43.0
v6.44.0
v6.45.0
v6.46.0
v6.46.1
v6.47.0
v6.48.0
v6.49.0
v6.5.0
v6.5.1
v6.50.0
v6.50.1
v6.51.0
v6.51.1
v6.51.2
v6.51.3
v6.52.0
v6.53.0
v6.53.1
v6.53.2
v6.54.0
v6.55.0
v6.56.0
v6.56.1
v6.57.0
v6.57.1
v6.58.0
v6.59.0
v6.6.0
v6.60.0
v6.61.0
v6.61.1
v6.61.2
v6.61.3
v6.61.4
v6.61.5
v6.61.6
v6.61.7
v6.62.0
v6.63.0
v6.63.1
v6.63.2
v6.64.0
v6.65.0
v6.65.1
v6.65.2
v6.65.3
v6.65.4
v6.66.0
v6.67.0
v6.68.0
v6.69.0
v6.69.1
v6.7.0
v6.7.1
v6.70.0
v6.71.0
v6.71.1
v6.71.2
v6.72.0
v6.73.0
v6.74.0
v6.75.0
v6.76.0
v6.77.0
v6.77.1
v6.78.0
v6.79.0
v6.8.0
v6.80.0
v6.80.1
v6.80.2
v6.81.0
v6.81.1
v6.82.0
v6.82.1
v6.83.0
v6.84.0
v6.84.1
v6.85.0
v6.85.1
v6.85.2
v6.86.0
v6.87.0
v6.88.0
v6.88.1
v6.88.2
v6.89.0
v6.9.0
v6.9.1
v6.90.0
v6.91.0
v6.92.0
v6.93.0

v7.*

v7.0.0
v7.1.0
v7.10.0
v7.10.1
v7.10.2
v7.11.0
v7.12.0
v7.12.1
v7.12.2
v7.12.3
v7.13.0
v7.14.0
v7.14.1
v7.14.2
v7.14.3
v7.15.0
v7.16.0
v7.17.0
v7.18.0
v7.19.0
v7.2.0
v7.20.0
v7.21.0
v7.21.1
v7.21.2
v7.22.0
v7.23.0
v7.23.1
v7.23.2
v7.24.0
v7.24.1
v7.25.0
v7.26.0
v7.3.0
v7.3.1
v7.3.2
v7.3.3
v7.4.0
v7.4.1
v7.5.0
v7.5.1
v7.6.0
v7.7.0
v7.8.0
v7.9.0

v8.*

v8.0.0
v8.1.0
v8.1.1
v8.10.0
v8.11.0
v8.12.0
v8.13.0
v8.13.1
v8.13.2
v8.13.3
v8.13.4
v8.14.0
v8.15.0
v8.15.1
v8.16.0
v8.17.0
v8.17.1
v8.18.0
v8.18.1
v8.19.0
v8.2.0
v8.2.1
v8.20.0
v8.20.1
v8.20.2
v8.20.3
v8.21.0
v8.22.0
v8.22.1
v8.23.0
v8.24.0
v8.24.1
v8.24.2
v8.24.3
v8.24.4
v8.24.5
v8.25.0
v8.25.1
v8.25.2
v8.26.0
v8.26.1
v8.26.2
v8.27.0
v8.28.0
v8.28.1
v8.28.2
v8.29.0
v8.29.1
v8.29.2
v8.29.3
v8.3.0
v8.3.1
v8.3.2
v8.30.0
v8.4.0
v8.4.1
v8.4.2
v8.4.3
v8.4.4
v8.5.0
v8.6.0
v8.6.1
v8.6.2
v8.7.0
v8.8.0
v8.8.1
v8.8.2
v8.8.3
v8.8.4
v8.8.5
v8.8.6
v8.8.7
v8.8.8
v8.9.0

v9.*

v9.0.0-beta.1
v9.1.0
v9.10.0
v9.10.1
v9.11.0
v9.12.0
v9.13.0
v9.14.0
v9.14.1
v9.15.0
v9.16.0
v9.16.1
v9.16.19
v9.16.2
v9.16.20
v9.16.3
v9.16.4
v9.16.5
v9.17.0
v9.17.1
v9.17.2
v9.17.3
v9.17.4
v9.17.5
v9.18.0
v9.18.1
v9.18.2
v9.19.0
v9.19.1
v9.2.0
v9.2.1
v9.20.0
v9.20.1
v9.20.2
v9.21.0
v9.22.0
v9.23.0
v9.23.1
v9.23.2
v9.23.3
v9.24.0
v9.24.1
v9.24.2
v9.24.3
v9.24.4
v9.24.5
v9.24.6
v9.24.7
v9.24.8
v9.25.0
v9.25.1
v9.26.0
v9.26.1
v9.26.2
v9.26.3
v9.26.4
v9.3.0
v9.4.0
v9.5.0
v9.6.0
v9.7.0
v9.8.0
v9.9.0
v9.9.1
v9.9.2