Metrics
Affected Vendors & Products
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 15 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Matrix-react-sdk Project
Matrix-react-sdk Project matrix-react-sdk |
|
CPEs | cpe:2.3:a:matrix-react-sdk_project:matrix-react-sdk:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Matrix-react-sdk Project
Matrix-react-sdk Project matrix-react-sdk |
|
Metrics |
cvssV3_1
|
Tue, 15 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-react-sdk before 3.102.0 shared historical message keys on invite. Version 3.102.0 fixes this issue by disabling sharing message keys on invite by removing calls to the vulnerable functionality. No known workarounds are available. | |
Title | Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-15T15:40:37.397Z
Updated: 2024-11-21T16:52:42.888Z
Reserved: 2024-10-03T14:06:12.641Z
Link: CVE-2024-47824
Updated: 2024-10-15T16:32:11.296Z
Status : Awaiting Analysis
Published: 2024-10-15T16:15:05.120
Modified: 2024-11-21T17:15:17.650
Link: CVE-2024-47824
No data.