Missing Authorization Affecting matrix-js-sdk package, versions <24.1.0
Threat Intelligence
EPSS
0.11% (45th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-MATRIXJSSDK-5425049
- published 16 Apr 2023
- disclosed 14 Apr 2023
- credit Unknown
Introduced: 14 Apr 2023
CVE-2023-29529 Open this link in a new tabHow to fix?
Upgrade matrix-js-sdk
to version 24.1.0 or higher.
Overview
matrix-js-sdk is a Matrix Client-Server SDK for Javascript
Affected versions of this package are vulnerable to Missing Authorization which can lead to invisible eavesdropping in group calls, on the video and audio of participants without their knowledge. The attacker will not appear to be participating in the call.
Notes: Legacy 1:1 calls are unaffected.
Workarounds
Users may hold group calls in private rooms where only the exact users who are expected to participate in the call are present.
References
CVSS Scores
version 3.1