CVE-2021-29501 is a sensitive information exposure vulnerability affecting the Ticketer cog (plugin) for the Red Discord bot, specifically versions prior to 1.0.1. This medium-severity vulnerability (CVSS 6.5) allows authenticated Discord users to remotely access sensitive information with low attack complexity and no user interaction required. While no public exploits or active exploitation have been observed, and community discussion is minimal, users should upgrade to version 1.0.1 or unload the Ticketer cog as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.1CPE matchmatch criteria | cpe:2.3:a:dav-cogs_project:dav-cogs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.