Lucene search

K

Javascript Sdk Security Vulnerabilities

cve
cve

CVE-2021-40823

A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients ...

5.9CVSS

5.4AI Score

0.001EPSS

2021-09-13 07:15 PM
68
cve
cve

CVE-2021-44538

The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted seq...

9.8CVSS

9.4AI Score

0.007EPSS

2021-12-14 02:15 PM
95
cve
cve

CVE-2022-36059

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safel...

8.2CVSS

6.4AI Score

0.0005EPSS

2023-03-28 09:15 PM
87
cve
cve

CVE-2022-39236

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sd...

5.3CVSS

6AI Score

0.001EPSS

2022-09-28 05:15 PM
75
7
cve
cve

CVE-2022-39249

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be mi...

7.5CVSS

7.3AI Score

0.001EPSS

2022-09-28 08:15 PM
84
3
cve
cve

CVE-2022-39250

Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one o...

8.6CVSS

7.4AI Score

0.001EPSS

2022-09-29 01:15 PM
91
2
cve
cve

CVE-2022-39251

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisti...

8.6CVSS

7.4AI Score

0.001EPSS

2022-09-28 08:15 PM
86
2
cve
cve

CVE-2023-28427

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safel...

8.2CVSS

8.1AI Score

0.004EPSS

2023-03-28 09:15 PM
96
cve
cve

CVE-2023-29529

matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker wil...

5.3CVSS

4.9AI Score

0.001EPSS

2023-04-14 07:15 PM
23