PT-2023-27903 · Unknown · Matrix Media Repo

Joshqou

·

Published

2023-09-08

·

Updated

2024-08-21

·

CVE-2023-41318

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions matrix-media-repo versions prior to 1.3.0
Description The issue allows an attacker to upload malicious media to the media repository, which is then served with Content-Disposition: inline upon download. This can be leveraged to execute scripts embedded in SVG content. The vulnerability can be exploited through the / matrix/media/(r0|v3)/download endpoint. Server operators that do not share a domain between matrix-media-repo and other services are not affected.
Recommendations For versions prior to 1.3.0, upgrade to v1.3.0 as soon as possible. As a temporary workaround for operators unable to upgrade, override the Content-Disposition header returned by matrix-media-repo to always use attachment.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-41318
GHSA-5CRW-6J7V-XC72
GO-2023-2053

Affected Products

Matrix Media Repo