Race Condition Affecting red-discordbot package, versions [,3.0.0rc3)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-REDDISCORDBOT-6978157
- published 22 May 2024
- disclosed 1 May 2024
- credit Unknown
How to fix?
Upgrade Red-DiscordBot
to version 3.0.0rc3 or higher.
Overview
Red-DiscordBot is an A highly customisable Discord bot
Affected versions of this package are vulnerable to Race Condition which could cause the dictionary to be written to change during serialization, braking the encoder.
References
CVSS Scores
version 3.1