Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvg8-m4x3-w6xr

Опубликовано: 12 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal

Summary

matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver.

Details

The Matrix specification demands homeservers to perform validation of the server-name and media-id components of MXC URIs with the intent to prevent path traversal. However, it is not mentioned that a similar check must also be performed on the client to prevent client-side path traversal. matrix-js-sdk fails to perform this validation.

Patches

Fixed in matrix-js-sdk 34.11.1.

Workarounds

None.

References

Пакеты

Наименование

matrix-js-sdk

npm
Затронутые версииВерсия исправления

< 34.11.1

34.11.1

EPSS

Процентиль: 70%
0.00647
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-22

Связанные уязвимости

ubuntu
около 1 года назад

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver. Fixed in matrix-js-sdk 34.11.1.

nvd
около 1 года назад

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver. Fixed in matrix-js-sdk 34.11.1.

debian
около 1 года назад

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for Jav ...

suse-cvrf
около 1 года назад

Security update for MozillaThunderbird

EPSS

Процентиль: 70%
0.00647
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-22