matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-react-sdk before 3.102.0 shared historical message keys on invite. Version 3.102.0 fixes this issue by disabling sharing message keys on invite by removing calls to the vulnerable functionality. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Matrix-react-sdk Project
Matrix-react-sdk Project matrix-react-sdk |
|
CPEs | cpe:2.3:a:matrix-react-sdk_project:matrix-react-sdk:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Matrix-react-sdk Project
Matrix-react-sdk Project matrix-react-sdk |
|
Metrics |
cvssV3_1
|
Tue, 15 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-react-sdk before 3.102.0 shared historical message keys on invite. Version 3.102.0 fixes this issue by disabling sharing message keys on invite by removing calls to the vulnerable functionality. No known workarounds are available. | |
Title | Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-15T15:40:37.397Z
Updated: 2024-11-21T16:52:42.888Z
Reserved: 2024-10-03T14:06:12.641Z
Link: CVE-2024-47824
Vulnrichment
Updated: 2024-10-15T16:32:11.296Z
NVD
Status : Awaiting Analysis
Published: 2024-10-15T16:15:05.120
Modified: 2024-11-21T17:15:17.650
Link: CVE-2024-47824
Redhat
No data.