CVE-2024-35237 is a high-severity vulnerability in MIT IdentiBot, an open-source Discord bot, affecting instances that are publicly accessible and unpatched. The flaw, identified as CWE-862 (Missing Authorization), allows any user to add a vulnerable IdentiBot instance to their server and execute commands to reveal sensitive personal information (e.g., full name) of MIT affiliates who have previously verified their identity with the bot. With a CVSS score of 7.5, the vulnerability has a network attack vector and low attack complexity, leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ZelnickB | Mit-Identibot | < 48e3e5e7ead6777fa75d57c7711c8e55b501c24eCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.