matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-react-sdk before 3.102.0 shared historical message keys on invite. Version 3.102.0 fixes this issue by disabling sharing message keys on invite by removing calls to the vulnerable functionality. No known workarounds are available.
History

Tue, 15 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Matrix-react-sdk Project
Matrix-react-sdk Project matrix-react-sdk
CPEs cpe:2.3:a:matrix-react-sdk_project:matrix-react-sdk:*:*:*:*:*:node.js:*:*
Vendors & Products Matrix-react-sdk Project
Matrix-react-sdk Project matrix-react-sdk
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Description matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-react-sdk before 3.102.0 shared historical message keys on invite. Version 3.102.0 fixes this issue by disabling sharing message keys on invite by removing calls to the vulnerable functionality. No known workarounds are available.
Title Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-15T15:40:37.397Z

Updated: 2024-11-21T16:52:42.888Z

Reserved: 2024-10-03T14:06:12.641Z

Link: CVE-2024-47824

cve-icon Vulnrichment

Updated: 2024-10-15T16:32:11.296Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-15T16:15:05.120

Modified: 2024-11-21T17:15:17.650

Link: CVE-2024-47824

cve-icon Redhat

No data.