Prototype pollution in matrix-react-sdk
CVE-2022-36060

8.2HIGH

Key Information:

Vendor

Matrix-org

Vendor
CVE Published:
28 March 2023

What is CVE-2022-36060?

The matrix-react-sdk, part of the Matrix chat protocol for React JavaScript, has a vulnerability that allows specially crafted string events to disrupt its functionality. This can lead to crashes of room or event tiles, impairing the user experience by preventing specific rooms or events from rendering, while other parts of the application may still appear operational. It is crucial for users to upgrade to version 3.53.0, as there are no effective workarounds available for this issue.

Affected Version(s)

matrix-react-sdk < 3.53.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.