First published: Tue Mar 28 2023(Updated: )
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered. This issue has been fixed in matrix-react-sdk 3.53.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Matrix React Sdk | <3.53.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36060 is a vulnerability in the matrix-react-sdk library that can cause crashes or disruptions in the application.
CVE-2022-36060 has a severity score of 5.3, which is considered high.
CVE-2022-36060 can temporarily disrupt or impede the matrix-react-sdk, causing crashes or issues with room or event tiles.
Versions of matrix-react-sdk up to and excluding 3.53.0 are affected by CVE-2022-36060.
To fix CVE-2022-36060, upgrade to a version of matrix-react-sdk that is beyond 3.53.0.