Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28103

Опубликовано: 28 мар. 2023
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the Object.prototype, disrupting matrix-react-sdk functionality, causing denial of service and potentially affecting program logic. This is fixed in matrix-react-sdk 3.69.0 and users are advised to upgrade. There are no known workarounds for this vulnerability. Note this advisory is distinct from GHSA-2x9c-qwgf-94xr which refers to a similar issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:matrix-react-sdk_project:matrix-react-sdk:*:*:*:*:*:node.js:*:*
Версия до 3.69.0 (исключая)

EPSS

Процентиль: 57%
0.00346
Низкий

8.2 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 8.2
github
почти 3 года назад

Prototype pollution in matrix-react-sdk

EPSS

Процентиль: 57%
0.00346
Низкий

8.2 High

CVSS3

Дефекты

CWE-1321