CVE-2024-42347: URL preview setting for a room is controllable by the homeserver in matrix-react-sdk
Impact A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server.
Even if the CVSS score would be 4.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N) the maintainer classifies this as High severity issue.
Patches This was patched in matrix-react-sdk 3.105.1.
Workarounds Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected.
References N/A.
Other sources
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42347?
CVE-2024-42347 has a CVSS score of 4.1, indicating a moderate severity level.
How do I fix CVE-2024-42347?
To fix CVE-2024-42347, upgrade the matrix-react-sdk to version 3.105.1 or later.
What type of vulnerability is CVE-2024-42347?
CVE-2024-42347 is a security vulnerability that allows malicious manipulation of user account data, specifically regarding URL previews in encrypted messages.
What software is affected by CVE-2024-42347?
CVE-2024-42347 affects the matrix-react-sdk version below 3.105.1.
What are the potential risks associated with CVE-2024-42347?
The potential risks of CVE-2024-42347 include unauthorized exposure of URLs in encrypted messages, compromising user privacy.