Lucene search

K
freebsdFreeBSD5B0AE405-CDC7-11ED-BB39-901B0E9408DC
HistoryMar 28, 2023 - 12:00 a.m.

Matrix clients -- Prototype pollution in matrix-js-sdk

2023-03-2800:00:00
vuxml.freebsd.org
13
matrix developers
security releases
high severity
prototype pollution
events
disruption
data safety

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

0.004 Low

EPSS

Percentile

73.1%

Matrix developers report:

Today we are issuing security releases of matrix-js-sdk and matrix-react-sdk
to patch a pair of High severity vulnerabilities (CVE-2023-28427 /
GHSA-mwq8-fjpf-c2gr for matrix-js-sdk and CVE-2023-28103 / GHSA-6g43-88cp-w5gv
for matrix-react-sdk).
The issues involve prototype pollution via events containing special strings
in key locations, which can temporarily disrupt normal functioning of matrix-js-sdk
and matrix-react-sdk, potentially impacting the consumer’s ability to process data
safely.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchelement-web< 1.11.26UNKNOWN
FreeBSDanynoarchcinny<= 2.2.4UNKNOWN

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

0.004 Low

EPSS

Percentile

73.1%