Description
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered. This issue has been fixed in matrix-react-sdk 3.53.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0837 | matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered. This issue has been fixed in matrix-react-sdk 3.53.0 and users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-2x9c-qwgf-94xr | matrix-react-sdk Prototype pollution vulnerability |
References
History
Tue, 18 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-18T19:56:49.200Z
Reserved: 2022-07-15T23:52:24.339Z
Link: CVE-2022-36060
Updated: 2024-08-03T09:52:00.311Z
Status : Modified
Published: 2023-03-28T21:15:10.223
Modified: 2024-11-21T07:12:17.523
Link: CVE-2022-36060
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA