GHSA-c7hh-3v6c-fj4q

    Dashboard / Vulnerabilities / GHSA-c7hh-3v6c-fj4q

    GHSA-c7hh-3v6c-fj4q

    Published: 4 Aug 2023Last Modified: 8 Nov 2023

    Summary: matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms

    Details: ### Impact It was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. ### Patches Please upgrade to 1.0.1. ### Workarounds You can set the `matrixHandler.eventCacheSize` config value to `0` to workaround this bug. However, this may impact performance. ### Credits Discovered and reported by [Val Lorentz](https://valentin-lorentz.fr/). ### For more information If you have any questions or comments about this advisory email us at [[email protected]](mailto:[email protected]).

    Affected packages

    Package

    Name: matrix-appservice-irc

    Purl: pkg:npm/matrix-appservice-irc

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.0.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-c7hh-3v6c-fj4q | CVE-DB