CVE-2022-39236Improper Input Validation in Javascript SDK

Severity
5.3MEDIUMNVD
CNA4.3OSV5.5
EPSS
0.5%
top 34.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateNov 11

Description

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This is patched in matrix-js-sdk v19.7.0. Redacting applicable events, waiting for the sync

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDmatrix/javascript_sdk17.1.019.7.0+1
npmmatrix-org/matrix-js-sdk17.1.0-rc.119.7.0
CVEListV5matrix-org/matrix-js-sdk>= 17.1.0-rc.1, < 19.7.0
Ubuntumozilla/thunderbird< 1:102.4.2+build2-0ubuntu0.18.04.1+2

Patches

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2022-11-11
GHSA
Improper beacon events in matrix-js-sdk can result in availability issues2022-09-29
OSV
Improper beacon events in matrix-js-sdk can result in availability issues2022-09-29
OSV
CVE-2022-39236: Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript2022-09-28
CVEList
Matrix Javascript SDK improper beacon events can cause availability issues2022-09-28

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2022-11-11
Red Hat
Mozilla: Matrix SDK bundled with Thunderbird vulnerable to a data corruption issue2022-09-28
Debian
CVE-2022-39236: node-matrix-js-sdk - Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting w...2022
Mozilla
Mozilla Foundation Security Advisory 2022-43: CVE-2022-39236
CVE-2022-39236 — Improper Input Validation | cvebase