PT-2025-4839 · Github · Github
Half-Shot
·
Published
2025-01-23
·
Updated
2025-01-27
·
CVE-2025-23197
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
matrix-hookshot versions 5.4.1 and earlier
matrix-hookshot versions 6.0.1 and earlier
Description
The issue is related to a Denial of Service (DoS) condition that can occur when the software is configured with GitHub support. This happens due to a missing check, allowing the software to crash on restart. The impact is greater when untrusted users can add their own GitHub organizations to connect their room to a repository. The vulnerability is exploited by insufficient validation of unusual or exceptional states when connecting to the GitHub platform, potentially allowing a remote attacker to cause a denial of service.
Recommendations
For matrix-hookshot version 5.4.1 and earlier, update to version 5.4.2 to resolve the issue.
For matrix-hookshot version 6.0.1 and earlier, update to version 6.0.2 to resolve the issue.
Exploit
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github