Prototype pollution in matrix-react-sdk
CVE-2023-28103

8.2HIGH

Key Information:

Vendor

Matrix-org

Vendor
CVE Published:
28 March 2023

What is CVE-2023-28103?

The matrix-react-sdk, a Matrix chat protocol SDK for React JavaScript, is susceptible to vulnerabilities when used in specific configurations. Data sent from remote servers may include specially crafted strings at critical points, leading to unintended alterations of the Object.prototype. This disruption can severely affect the functionality of the matrix-react-sdk, resulting in potential Denial of Service (DoS) conditions. Users are strongly encouraged to upgrade to version 3.69.0 or later as there are no known workarounds. For further details, please refer to the official advisory.

Affected Version(s)

matrix-react-sdk < 3.69.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.