Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7hh-3v6c-fj4q

Опубликовано: 04 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 3.5

Описание

matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms

Impact

It was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target.

Patches

Please upgrade to 1.0.1.

Workarounds

You can set the matrixHandler.eventCacheSize config value to 0 to workaround this bug. However, this may impact performance.

Credits

Discovered and reported by Val Lorentz.

For more information

If you have any questions or comments about this advisory email us at security@matrix.org.

Пакеты

Наименование

matrix-appservice-irc

npm
Затронутые версииВерсия исправления

<= 1.0.0

1.0.1

EPSS

Процентиль: 50%
0.00266
Низкий

3.5 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.5
nvd
больше 2 лет назад

matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the `matrixHandler.eventCacheSize` config value to `0`. This workaround may impact performance.

EPSS

Процентиль: 50%
0.00266
Низкий

3.5 Low

CVSS3

Дефекты

CWE-200