Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-c7hh-3v6c-fj4q: matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms

Impact

It was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target.

Patches

Please upgrade to 1.0.1.

Workarounds

You can set the matrixHandler.eventCacheSize config value to 0 to workaround this bug. However, this may impact performance.

Credits

Discovered and reported by Val Lorentz.

For more information

If you have any questions or comments about this advisory email us at [email protected].

ghsa
#vulnerability#nodejs#git

Skip to content

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
  • Pricing
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-38700

matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms

Package

npm matrix-appservice-irc (npm)

Affected versions

<= 1.0.0

Description

Impact

It was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target.

Patches

Please upgrade to 1.0.1.

Workarounds

You can set the matrixHandler.eventCacheSize config value to 0 to workaround this bug. However, this may impact performance.

Credits

Discovered and reported by Val Lorentz.

For more information

If you have any questions or comments about this advisory email us at [email protected].

References

  • GHSA-c7hh-3v6c-fj4q
  • matrix-org/matrix-appservice-irc@8bbd2b6

Published to the GitHub Advisory Database

Aug 4, 2023

ghsa: Latest News

GHSA-f679-254h-qhvj: Leantime allows Cross-Site Scripting (XSS)