GHSA-grvv-h2f9-7v9c

    Dashboard / Vulnerabilities / GHSA-grvv-h2f9-7v9c

    GHSA-grvv-h2f9-7v9c

    Published: 30 Aug 2022Last Modified: 8 Nov 2023

    Summary: gomatrixserverlib and Dendrite vulnerable to incorrect parsing of the event default power level in event auth

    Details: ### Impact The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to zero in all cases. In rooms where the `"events_default"` power level had been changed, this could result in events either being incorrectly authorised or rejected by Dendrite servers. ### Patches gomatrixserverlib contains a fix as of commit `723fd49` and Dendrite 0.9.3 has been updated accordingly. ### Workarounds Matrix rooms where the `"events_default"` power level has not been changed from the default of zero are not vulnerable. ### For more information If you have any questions or comments about this advisory, e-mail us at [[email protected]](mailto:[email protected]).

    Affected packages

    Package

    Name: github.com/matrix-org/dendrite

    Purl: pkg:golang/github.com/matrix-org/dendrite

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.9.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-grvv-h2f9-7v9c | CVE-DB