Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f83w-wqhc-cfp4

Опубликовано: 06 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 4.1

Описание

Matrix SDK for React's URL preview setting for a room is controllable by the homeserver

Impact

A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server.

Even if the CVSS score would be 4.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N) the maintainer classifies this as High severity issue.

Patches

This was patched in matrix-react-sdk 3.105.1.

Workarounds

Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected.

References

N/A.

Пакеты

Наименование

matrix-react-sdk

npm
Затронутые версииВерсия исправления

< 3.105.1

3.105.1

EPSS

Процентиль: 73%
0.00766
Низкий

5.1 Medium

CVSS4

4.1 Medium

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 7.7
nvd
больше 1 года назад

matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 73%
0.00766
Низкий

5.1 Medium

CVSS4

4.1 Medium

CVSS3

Дефекты

CWE-359