cbcvebase.
CVE-2023-28427
published 2023-03-28

CVE-2023-28427: matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can…

PriorityP343high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
1.19%
64.3th percentile
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannode-matrix-js-sdk< thunderbird 1:102.9.1-1 (bookworm)thunderbird 1:102.9.1-1 (bookworm)
debianthunderbird< thunderbird 1:102.9.1-1 (bookworm)thunderbird 1:102.9.1-1 (bookworm)
matrix-orgmatrix-js-sdk< 24.0.024.0.0
matrix-orgmatrix-js-sdk>= 0 < 24.0.024.0.0
matrixjavascript_sdk< 24.0.024.0.0
mozillafirefox
mozillathunderbird>= 0 < 1:102.10.0-1~deb11u11:102.10.0-1~deb11u1
mozillathunderbird>= 0 < 1:102.9.1-11:102.9.1-1
mozillathunderbird>= 0 < 1:102.9.1-11:102.9.1-1
mozillathunderbird>= 0 < 1:102.9.1-11:102.9.1-1

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
ghsa5.3MEDIUM
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.