CVE-2024-42369

CVSS V2 None CVSS V3 None
Description
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but also called by the 'leaveRoomChain()' method, so leaving a room will also trigger the bug. This was patched in matrix-js-sdk 34.3.1.
Overview
  • CVE ID
  • CVE-2024-42369
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-20T14:37:19.226Z
  • Last Modified Date
  • 2024-08-20T14:37:19.226Z
History
Created Old Value New Value Data Type Notes
2024-08-21 13:16:55 Added to TrackCVE