matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Mon, 12 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Matrix
Matrix matrix-react-sdk
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:matrix:matrix-react-sdk:*:*:*:*:*:*:*:*
Vendors & Products Matrix
Matrix matrix-react-sdk

Thu, 08 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Aug 2024 17:30:00 +0000

Type Values Removed Values Added
Description matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Title URL preview setting for a room is controllable by the homeserver in matrix-react-sdk
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-06T17:16:14.143Z

Updated: 2024-08-08T18:48:19.919Z

Reserved: 2024-07-30T14:01:33.921Z

Link: CVE-2024-42347

cve-icon Vulnrichment

Updated: 2024-08-08T18:48:11.316Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-06T18:15:57.103

Modified: 2024-08-12T18:52:08.163

Link: CVE-2024-42347

cve-icon Redhat

No data.