PT-2021-22420 · Matrix+1 · Matrix+1
0Xkasper
·
Published
2021-08-31
·
Updated
2024-06-15
·
CVE-2021-39163
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Matrix versions 1.41.0 and prior
Description
Unauthorised users can access the name, avatar, topic, and number of members of a room if they know the ID of the room. This issue is limited to homeservers where the vulnerable homeserver is in the room and untrusted users are permitted to create groups, which requires the configuration setting
enable group creation to be set to true. By default, only homeserver administrators can create groups, and they already have access to this information through the database or admin API.Recommendations
To patch the vulnerability, server administrators should upgrade to version 1.41.1 or higher.
As a temporary workaround, server administrators can set
enable group creation to false in their homeserver configuration to prevent creation of groups by non-administrators.
Administrators using a reverse proxy can block the endpoints / matrix/client/r0/groups/{group id}/rooms and / matrix/client/unstable/groups/{group id}/rooms to minimize the risk, albeit with partial loss of group functionality.Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Matrix