CVE-2021-21431 - CVE House
Back to Database
Status published High CVE-2021-21431

Improper Input Validation in sopel-plugins.channelmgnt

Vulnerability Description

sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple users at once. We also believe it may have been possible to remove users from other channels but due to the wonder that is IRC and following RfCs, We have no POC for that. Freenode is not affected. This is fixed in version 2.0.1. As a workaround, do not use this plugin on networks where TARGMAX > 1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-21431

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

MirahezeBots

View all reports →

Affected Software

sopel-channelmgnt
Vulnerable Versions:
< 2.0.1

Timeline

Official Publish: April 9th, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H

Weaknesses (CWE)