CVE-2022-21669 describes a critical vulnerability in PuddingBot versions 0.0.6-b933652 and prior, where the bot's authentication token was publicly exposed in the main.py file. This exposure allowed unauthorized access to the bot, posing a significant risk of compromise. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity and high confidentiality impact, as an attacker could gain full control of the bot. While the bot token has been revoked and a new version is running, the code update is pending. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.0.6-b933652CPE matchmatch criteria | cpe:2.3:a:puddingbot_project:puddingbot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.