PT-2022-24988 · Unknown · Matrix-Appservice-Irc

Jaller94

·

Published

2022-11-13

·

Updated

2022-11-17

·

CVE-2022-3971

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions matrix-appservice-irc versions up to 0.35.1
Description A critical issue affects the file src/datastore/postgres/PgDataStore.ts, where the manipulation of the roomIds argument leads to sql injection. Upgrading to version 0.36.0 addresses this issue.
Recommendations For matrix-appservice-irc versions up to 0.35.1, upgrade to version 0.36.0 to address the issue. As a temporary workaround, consider restricting the manipulation of the roomIds argument to minimize the risk of sql injection.

Fix

Improper Neutralization

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-3971
GHSA-FFWF-47X2-JPR8

Affected Products

Matrix-Appservice-Irc