PT-2021-22420 · Matrix+1 · Matrix+1

0Xkasper

·

Published

2021-08-31

·

Updated

2024-06-15

·

CVE-2021-39163

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Matrix versions 1.41.0 and prior
Description Unauthorised users can access the name, avatar, topic, and number of members of a room if they know the ID of the room. This issue is limited to homeservers where the vulnerable homeserver is in the room and untrusted users are permitted to create groups, which requires the configuration setting enable group creation to be set to true. By default, only homeserver administrators can create groups, and they already have access to this information through the database or admin API.
Recommendations To patch the vulnerability, server administrators should upgrade to version 1.41.1 or higher. As a temporary workaround, server administrators can set enable group creation to false in their homeserver configuration to prevent creation of groups by non-administrators. Administrators using a reverse proxy can block the endpoints / matrix/client/r0/groups/{group id}/rooms and / matrix/client/unstable/groups/{group id}/rooms to minimize the risk, albeit with partial loss of group functionality.

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2675
CVE-2021-39163
GHSA-JJ53-8FMW-F2W2
OPENSUSE-SU-2024:11041-1
PYSEC-2021-424

Affected Products

Alt Linux
Matrix