CVE-2022-36059
published 2023-03-28CVE-2022-36059: matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.94%
57.0th percentile
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This issue has been fixed in matrix-js-sdk 19.4.0 and users are advised to upgrade. Users unable to upgrade may mitigate this issue by redacting applicable events, waiting for the sync processor to store data, and restarting the client. Alternatively, redacting the applicable events and clearing all storage will often fix most perceived issues. In some cases, no workarounds are possible.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-matrix-js-sdk | < thunderbird 1:102.2.1-1 (bookworm) | thunderbird 1:102.2.1-1 (bookworm) |
| debian | thunderbird | < thunderbird 1:102.2.1-1 (bookworm) | thunderbird 1:102.2.1-1 (bookworm) |
| matrix-org | matrix-js-sdk | < 19.4.0 | 19.4.0 |
| matrix-org | matrix-js-sdk | >= 0 < 19.4.0 | 19.4.0 |
| matrix-org | matrix-js-sdk | >= 0 < 24.0.0 | 24.0.0 |
| matrix | javascript_sdk | < 19.4.0 | 19.4.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.18.04.1 | 1:102.2.2+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.20.04.1 | 1:102.2.2+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.22.04.1 | 1:102.2.2+build1-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
ghsa5.3MEDIUM
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2022-10-07·CVSS 8.8
CVE-2022-36059 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
spoof the mouse pointer position, obtain sensitive information, spoof the
contents of the addressbar, bypass security restrictions, or execute
arbitrary code. (CVE-2022-2505, CVE-2022-36318, CVE-2022-36319,
CVE-2022-38472, CVE-2022-38473, CVE-2022-38476 CVE-2022-38477,
CVE-2022-38478)
Multiple security issues were discovered in Thunderbird. An attacker could
potentially exploit these in order to determine when a user opens a
specially crafted message. (CVE-2022-3032, CVE-2022-303
Red Hat
Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack
vendor_redhat·2022-08-31·CVSS 8.2
CVE-2022-36059 [HIGH] CWE-440 Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack
Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This issue has been fixed in matrix-js-sdk 19.4.0 and users are advised to upgrade. Users unable to upgrade may mitigate this issue by redacting applicable events, waiting for the sync processor to store data, and restarting the client. Alternatively, redacting the applicable e
Debian
CVE-2022-36059: node-matrix-js-sdk - matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. I...
vendor_debian·2022·CVSS 8.2
CVE-2022-36059 [HIGH] CVE-2022-36059: node-matrix-js-sdk - matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. I...
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This issue has been fixed in matrix-js-sdk 19.4.0 and users are advised to upgrade. Users unable to upgrade may mitigate this issue by redacting applicable events, waiting for the sync processor to store data, and restarting the client. Alternatively, redacting the applicable events and clearing all storage will often fix most perceived issues. In some cases, n
Mozilla
Mozilla Foundation Security Advisory 2022-38: CVE-2022-36059
vendor_mozilla·CVSS 8.2
CVE-2022-36059 [HIGH] Mozilla Foundation Security Advisory 2022-38: CVE-2022-36059
Mozilla Foundation Security Advisory 2022-38
CVE: CVE-2022-36059
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 102.2.1
OSV
Prototype pollution in matrix-js-sdk (part 2)
osv·2023-03-30·CVSS 5.3
CVE-2023-28427 [MEDIUM] Prototype pollution in matrix-js-sdk (part 2)
Prototype pollution in matrix-js-sdk (part 2)
### Impact
In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-js-sdk functionality, causing denial of service and potentially affecting program logic.
(This is part 2, where [CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059) / [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) is part 1. Part 2 covers remaining vectors not covered by part 1, found in a codebase audit scheduled after part 1.)
### Patches
The issue has been patched in matrix-js-sdk 24.0.0.
### Workarounds
None.
### References
- [Release blog post](https://matrix.org/blog/2
GHSA
Prototype pollution in matrix-js-sdk (part 2)
ghsa·2023-03-30·CVSS 5.3
CVE-2023-28427 [MEDIUM] CWE-1321 Prototype pollution in matrix-js-sdk (part 2)
Prototype pollution in matrix-js-sdk (part 2)
### Impact
In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-js-sdk functionality, causing denial of service and potentially affecting program logic.
(This is part 2, where [CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059) / [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) is part 1. Part 2 covers remaining vectors not covered by part 1, found in a codebase audit scheduled after part 1.)
### Patches
The issue has been patched in matrix-js-sdk 24.0.0.
### Workarounds
None.
### References
- [Release blog post](https://matrix.org/blog/2
GHSA
matrix-js-sdk Prototype Pollution vulnerability
ghsa·2023-03-28
CVE-2022-36059 [HIGH] CWE-1321 matrix-js-sdk Prototype Pollution vulnerability
matrix-js-sdk Prototype Pollution vulnerability
### Impact
Events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer.
### Patches
This is fixed in matrix-js-sdk 19.4.0.
### Workarounds
Redacting applicable events, waiting for the sync processor to store data, and restarting the client can often fix it. Alternatively, redacting the applicable events and clearing all storage will often fix most perceived issues.
In some cases, no workarounds are possible.
### References
https://learn.snyk.io/lessons/prototype-pollution/j
OSV
matrix-js-sdk Prototype Pollution vulnerability
osv·2023-03-28
CVE-2022-36059 [HIGH] matrix-js-sdk Prototype Pollution vulnerability
matrix-js-sdk Prototype Pollution vulnerability
### Impact
Events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer.
### Patches
This is fixed in matrix-js-sdk 19.4.0.
### Workarounds
Redacting applicable events, waiting for the sync processor to store data, and restarting the client can often fix it. Alternatively, redacting the applicable events and clearing all storage will often fix most perceived issues.
In some cases, no workarounds are possible.
### References
https://learn.snyk.io/lessons/prototype-pollution/j
OSV
CVE-2022-36059: matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript
osv·2023-03-28·CVSS 5.3
CVE-2022-36059 [MEDIUM] CVE-2022-36059: matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This issue has been fixed in matrix-js-sdk 19.4.0 and users are advised to upgrade. Users unable to upgrade may mitigate this issue by redacting applicable events, waiting for the sync processor to store data, and restarting the client. Alternatively, redacting the applicable events and clearing all storage will often fix most perceived issues. In some cases, n
OSV
thunderbird vulnerabilities
osv·2022-10-07·CVSS 8.8
CVE-2022-2505 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
spoof the mouse pointer position, obtain sensitive information, spoof the
contents of the addressbar, bypass security restrictions, or execute
arbitrary code. (CVE-2022-2505, CVE-2022-36318, CVE-2022-36319,
CVE-2022-38472, CVE-2022-38473, CVE-2022-38476 CVE-2022-38477,
CVE-2022-38478)
Multiple security issues were discovered in Thunderbird. An attacker could
potentially exploit these in order to determine when a user opens a
specially crafted message. (CVE-2022-3032, CVE-2022-3034)
It was discovered that Thunderbird did not correctly handle HTML
No detection rules found.
No public exploits indexed.
2023-03-28
Published