PT-2024-29884 · Unknown · Matrix-React-Sdk
Published
2024-08-06
·
Updated
2024-08-18
·
CVE-2024-42347
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
matrix-react-sdk versions prior to 3.105.0
Description
A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected.
Recommendations
For versions prior to 3.105.0, upgrade to version 3.105.0 or later to resolve the issue. As a temporary workaround, consider disabling URL previews in end-to-end encrypted rooms until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matrix-React-Sdk