Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52mq-6jcv-j79x

Опубликовано: 03 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 2.6

Описание

User content sandbox can be confused into opening arbitrary documents

Impact

The user content sandbox can be abused to trick users into opening unexpected documents after several user interactions. The content can be opened with a blob origin from the Matrix client, so it is possible for a malicious document to access user messages and secrets.

Patches

This has been fixed by https://github.com/matrix-org/matrix-react-sdk/pull/5657, which is included in 3.15.0.

Workarounds

There are no known workarounds.

Пакеты

Наименование

matrix-react-sdk

npm
Затронутые версииВерсия исправления

< 3.15.0

3.15.0

EPSS

Процентиль: 40%
0.00185
Низкий

2.6 Low

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 2.6
nvd
почти 5 лет назад

matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.

EPSS

Процентиль: 40%
0.00185
Низкий

2.6 Low

CVSS3

Дефекты

CWE-345