CVE-2022-21669
Published on: 01/11/2022 12:00:00 AM UTC
Last Modified on: 08/02/2023 05:26:00 PM UTC
Certain versions of Puddingbot from Puddingbot Project contain the following vulnerability:
PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the server. As of time of publication, the maintainers are planning to update code to reflect this change at a later date.
- CVE-2022-21669 has been assigned by
security-adviso[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
PuddingBot - pudding-bot version <= 0.0.6-b933652
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Merge pull request #15 from PuddingBot/CVE-2022-21669 · PuddingBot/pudding-bot@a5b15fb · GitHub | github.com text/html |
![]() |
Bot token exposed in main.py · Advisory · PuddingBot/pudding-bot · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Puddingbot Project | Puddingbot | All | All | All | All |
- cpe:2.3:a:puddingbot_project:puddingbot:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-21669 : PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicl… twitter.com/i/web/status/1… | 2022-01-11 15:00:49 |
![]() |
CVE-2022-21669 | 2022-01-11 15:38:49 |