PT-2024-7453 · Unknown · Matrix-React-Sdk
Dkasak
·
Published
2024-06-14
·
Updated
2024-10-17
·
CVE-2024-47824
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
matrix-react-sdk versions 3.18.0 through 3.101.9
Description:
The issue is related to insufficient protection of service data, allowing a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room. This is possible because matrix-react-sdk before version 3.102.0 shared historical message keys on invite.
Recommendations:
For versions 3.18.0 through 3.101.9, update to version 3.102.0 to prevent the potential theft of message keys by a malicious homeserver during room invites.
As a temporary workaround, consider disabling the sharing of message keys on invite until a patch is available.
Restrict access to the vulnerable functionality to minimize the risk of exploitation.
Avoid using the vulnerable version of matrix-react-sdk until the issue is resolved.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matrix-React-Sdk