CVE-2024-42369
- EPSS 0.21%
- Published 20.08.2024 15:15:21
- Last modified 21.08.2024 16:01:03
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recur...
CVE-2023-29529
- EPSS 0.18%
- Published 14.04.2023 19:15:09
- Last modified 21.11.2024 07:57:14
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. ...
CVE-2023-28427
- EPSS 0.27%
- Published 28.03.2023 21:15:11
- Last modified 21.11.2024 07:55:02
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impac...
CVE-2022-36059
- EPSS 0.87%
- Published 28.03.2023 21:15:10
- Last modified 21.11.2024 07:12:17
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impac...
CVE-2022-39250
- EPSS 0.13%
- Published 29.09.2022 13:15:09
- Last modified 21.11.2024 07:17:52
Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its ...
CVE-2022-39249
- EPSS 0.14%
- Published 28.09.2022 20:15:16
- Last modified 21.11.2024 07:17:52
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a ...
CVE-2022-39251
- EPSS 0.14%
- Published 28.09.2022 20:15:16
- Last modified 21.11.2024 07:17:52
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indicatio...
CVE-2022-39236
- EPSS 0.07%
- Published 28.09.2022 17:15:11
- Last modified 21.11.2024 07:17:50
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability t...
CVE-2021-44538
- EPSS 1.42%
- Published 14.12.2021 14:15:09
- Last modified 21.11.2024 06:31:11
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of t...
CVE-2021-40823
- EPSS 0.26%
- Published 13.09.2021 19:15:19
- Last modified 21.11.2024 06:24:50
A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that...