PT-2023-28902 · Github+2 · Github+2
Half-Shot
·
Publicado
2023-09-27
·
Atualizado
2023-10-05
·
CVE-2023-43656
CVSS v3.1
5.6
Média
| Vetor | AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
matrix-hookshot versions prior to 4.5.0
Description
The issue affects matrix-hookshot, a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances with enabled transformation functions, specifically those that have
generic.allowJsTransformationFunctions in their config, may be vulnerable to an attack where it is possible to break out of the vm2 sandbox. This problem is more likely to affect users who have allowed untrusted users to apply their own transformation functions. The threat is reduced, though not eliminated, for users who have only enabled a limited set of trusted users.Recommendations
For versions prior to 4.5.0, upgrade to version 4.5.0 or above, which includes a new sandbox library for better protection.
For users unable to upgrade, disable
generic.allowJsTransformationFunctions in the config as a temporary workaround.Exploit
Correção
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Github
Gitlab
Jira