CVE-2023-29529
published 2023-04-14CVE-2023-29529: matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.54%
42.0th percentile
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call. This attack is possible because matrix-js-sdk's group call implementation accepts incoming direct calls from other users, even if they have not yet declared intent to participate in the group call, as a means of resolving a race condition in call setup. Affected versions do not restrict access to the user's outbound media in this case. Legacy 1:1 calls are unaffected. This is fixed in matrix-js-sdk 24.1.0. As a workaround, users may hold group calls in private rooms where only the exact users who are expected to participate in the call are present.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-matrix-js-sdk | — | — |
| matrix-org | matrix-js-sdk | < 24.1.0 | 24.1.0 |
| matrix-org | matrix-js-sdk | >= 0 < 24.1.0 | 24.1.0 |
| matrix | javascript_sdk | < 24.1.0 | 24.1.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-29529: matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript
osv·2023-04-14·CVSS 5.3
CVE-2023-29529 [MEDIUM] CVE-2023-29529: matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call. This attack is possible because matrix-js-sdk's group call implementation accepts incoming direct calls from other users, even if they have not yet declared intent to participate in the group call, as a means of resolving a race condition in call setup. Affected versions do not restrict access to the user's outbound media in this case. Legacy 1:1 calls are unaffected. This is fixed in matrix-js-sdk 24.1.0. As a workaround, users may hold group calls i
GHSA
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
ghsa·2023-04-14
CVE-2023-29529 [MEDIUM] CWE-862 matrix-js-sdk vulnerable to invisible eavesdropping in group calls
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
### Impact
An attacker present in a room where an [MSC3401](https://github.com/matrix-org/matrix-spec-proposals/pull/3401) group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call.
This attack is possible because matrix-js-sdk's group call implementation accepts incoming direct calls from other users, even if they have not yet declared intent to participate in the group call, as a means of resolving a race condition in call setup. Affected versions do not restrict access to the user's outbound media in this case.
Legacy 1:1 calls are unaffected.
### Workaroun
OSV
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
osv·2023-04-14
CVE-2023-29529 [MEDIUM] matrix-js-sdk vulnerable to invisible eavesdropping in group calls
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
### Impact
An attacker present in a room where an [MSC3401](https://github.com/matrix-org/matrix-spec-proposals/pull/3401) group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call.
This attack is possible because matrix-js-sdk's group call implementation accepts incoming direct calls from other users, even if they have not yet declared intent to participate in the group call, as a means of resolving a race condition in call setup. Affected versions do not restrict access to the user's outbound media in this case.
Legacy 1:1 calls are unaffected.
### Workaroun
Debian
CVE-2023-29529: node-matrix-js-sdk - matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An ...
vendor_debian·2023·CVSS 5.0
CVE-2023-29529 [MEDIUM] CVE-2023-29529: node-matrix-js-sdk - matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An ...
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call. This attack is possible because matrix-js-sdk's group call implementation accepts incoming direct calls from other users, even if they have not yet declared intent to participate in the group call, as a means of resolving a race condition in call setup. Affected versions do not restrict access to the user's outbound media in this case. Legacy 1:1 calls are unaffected. This is fixed in matrix-js-sdk 24.1.0. As a workaround, users may hold group calls i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/matrix-js-sdk/releases/tag/v24.1.0https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-6g67-q39g-r79qhttps://github.com/matrix-org/matrix-spec-proposals/pull/3401https://github.com/matrix-org/matrix-js-sdk/releases/tag/v24.1.0https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-6g67-q39g-r79qhttps://github.com/matrix-org/matrix-spec-proposals/pull/3401
2023-04-14
Published