PT-2022-24988 · Unknown · Matrix-Appservice-Irc
Jaller94
·
Published
2022-11-13
·
Updated
2022-11-17
·
CVE-2022-3971
CVSS v3.1
5.6
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
matrix-appservice-irc versions up to 0.35.1
Description
A critical issue affects the file src/datastore/postgres/PgDataStore.ts, where the manipulation of the
roomIds argument leads to sql injection. Upgrading to version 0.36.0 addresses this issue.Recommendations
For matrix-appservice-irc versions up to 0.35.1, upgrade to version 0.36.0 to address the issue. As a temporary workaround, consider restricting the manipulation of the
roomIds argument to minimize the risk of sql injection.Fix
Improper Neutralization
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Matrix-Appservice-Irc