漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Possibility to retrieve bot token by malicious module developers in Discord-Bot-Framework-Kernel
Vulnerability Description
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malicious code to perform damage or extract sensitive information. By loading the module containing the following code and run the command, the bot token can be extracted. Then the attacker can load a blocking module to sabotage the bot (DDoS attack) and the token can be used to make the fake bot act as the real one. If the bot has very high privilege, the attacker basically has full control before the user kicks the bot. Any Discord user that hosts Discord-Bot-Framework-Kernel before commit f0d9e70841a0e3170b88c4f8d562018ccd8e8b14 is affected. Users are advised to upgrade. Users unable to upgrade may attempt to limit their discord bot's access via configuration options.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:H
Vulnerability Type
信息暴露
Vulnerability Title
Discord Bot Framework Kernel 信息泄露漏洞
Vulnerability Description
Discord Bot Framework Kernel是Discord Agora开源的一个 Discord Bot 框架内核。 Discord Bot Framework Kernel存在信息泄露漏洞,该漏洞源于未正确处理用户提交的代码。攻击者利用该漏洞可以提取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A