Missing Authorization Affecting matrix-js-sdk package, versions <24.1.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-MATRIXJSSDK-5425049
  • published16 Apr 2023
  • disclosed14 Apr 2023
  • creditUnknown

Introduced: 14 Apr 2023

CVE-2023-29529  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade matrix-js-sdk to version 24.1.0 or higher.

Overview

matrix-js-sdk is a Matrix Client-Server SDK for Javascript

Affected versions of this package are vulnerable to Missing Authorization which can lead to invisible eavesdropping in group calls, on the video and audio of participants without their knowledge. The attacker will not appear to be participating in the call.

Notes: Legacy 1:1 calls are unaffected.

Workarounds

Users may hold group calls in private rooms where only the exact users who are expected to participate in the call are present.

References

CVSS Scores

version 3.1