matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 12 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Matrix
Matrix matrix-react-sdk |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:matrix:matrix-react-sdk:*:*:*:*:*:*:*:* | |
Vendors & Products |
Matrix
Matrix matrix-react-sdk |
Thu, 08 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 06 Aug 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | URL preview setting for a room is controllable by the homeserver in matrix-react-sdk | |
Weaknesses | CWE-359 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-06T17:16:14.143Z
Updated: 2024-08-08T18:48:19.919Z
Reserved: 2024-07-30T14:01:33.921Z
Link: CVE-2024-42347
Vulnrichment
Updated: 2024-08-08T18:48:11.316Z
NVD
Status : Analyzed
Published: 2024-08-06T18:15:57.103
Modified: 2024-08-12T18:52:08.163
Link: CVE-2024-42347
Redhat
No data.