Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
History

Tue, 12 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
Description Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
Title Element allows a malicious homeserver can modify events leading to unrenderable events or rooms
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-12T16:34:27.928Z

Updated: 2024-11-12T17:12:21.715Z

Reserved: 2024-10-31T14:12:45.790Z

Link: CVE-2024-51750

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T17:15:10.130

Modified: 2024-11-13T17:01:58.603

Link: CVE-2024-51750

cve-icon Redhat

No data.