Arbitrary Code Injection Affecting element-web package, versions <1.11.30-r0


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.09% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE320-ELEMENTWEB-7009298
  • published23 May 2024
  • disclosed25 Apr 2023

Introduced: 25 Apr 2023

CVE-2023-30609  (opens in a new tab)
CWE-74  (opens in a new tab)

How to fix?

Upgrade Alpine:3.20 element-web to version 1.11.30-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream element-web package and not the element-web package as distributed by Alpine. See How to fix? for Alpine:3.20 relevant fixed versions and status.

matrix-react-sdk is a react-based SDK for inserting a Matrix chat/VoIP client into a web page. Prior to version 3.71.0, plain text messages containing HTML tags are rendered as HTML in the search results. To exploit this, an attacker needs to trick a user into searching for a specific message containing an HTML injection payload. No cross-site scripting attack is possible due to the hardcoded content security policy. Version 3.71.0 of the SDK patches over the issue. As a workaround, restarting the client will clear the HTML injection.

CVSS Scores

version 3.1