PT-2024-29884 · Unknown · Matrix-React-Sdk

Published

2024-08-06

·

Updated

2024-08-18

·

CVE-2024-42347

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions matrix-react-sdk versions prior to 3.105.0
Description A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected.
Recommendations For versions prior to 3.105.0, upgrade to version 3.105.0 or later to resolve the issue. As a temporary workaround, consider disabling URL previews in end-to-end encrypted rooms until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42347
GHSA-F83W-WQHC-CFP4
OPENSUSE-SU-2024:14242-1
OPENSUSE-SU-2024:14273-1

Affected Products

Matrix-React-Sdk