{"id":"CVE-2022-24976","details":"Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.","modified":"2026-07-15T02:04:57.369907181Z","published":"2022-02-13T06:20:02Z","related":["openSUSE-SU-2022:10018-1","openSUSE-SU-2022:10019-1","openSUSE-SU-2024:11848-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24976.json"},"references":[{"type":"WEB","url":"https://github.com/atheme/atheme/compare/v7.2.11...v7.2.12"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2022/01/30/4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24976.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24976"},{"type":"FIX","url":"https://github.com/atheme/atheme/commit/4e664c75d0b280a052eb8b5e81aa41944e593c52"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/atheme/atheme","events":[{"introduced":"5644554cf3b2de7ebb6ab24a01eef4edc4b2a7eb"},{"fixed":"937b61ee1a3b6117dd447a4922441872ee2d9b9d"},{"fixed":"4e664c75d0b280a052eb8b5e81aa41944e593c52"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:atheme:atheme:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.2.0"},{"fixed":"7.2.12"}]}}],"versions":["v7.2.11","v7.2.10-r2","v7.2.9","v7.2.8","v7.2.7","atheme-7.2.6","atheme-7.2.5","atheme-7.2.4","atheme-7.2.3","atheme-7.2.2","atheme-7.2.1","atheme-7.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24976.json"}}],"schema_version":"1.7.5"}