CVE-2024-42347: URL preview setting for a room is controllable by the homeserver in matrix-react-sdk

Published Aug 6, 2024
·
Updated

Impact A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server.

Even if the CVSS score would be 4.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N) the maintainer classifies this as High severity issue.

Patches This was patched in matrix-react-sdk 3.105.1.

Workarounds Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected.

References N/A.

Other sources

matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.

MITRE

Affected Software

2 affected componentsFixes available
npm/matrix-react-sdk<3.105.1
3.105.1
matrix matrix-react-sdk<3.105.1

Event History

Aug 6, 2024
Advisory Published
via GitHub·02:12 PM
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-42347?

CVE-2024-42347 has a CVSS score of 4.1, indicating a moderate severity level.

2

How do I fix CVE-2024-42347?

To fix CVE-2024-42347, upgrade the matrix-react-sdk to version 3.105.1 or later.

3

What type of vulnerability is CVE-2024-42347?

CVE-2024-42347 is a security vulnerability that allows malicious manipulation of user account data, specifically regarding URL previews in encrypted messages.

4

What software is affected by CVE-2024-42347?

CVE-2024-42347 affects the matrix-react-sdk version below 3.105.1.

5

What are the potential risks associated with CVE-2024-42347?

The potential risks of CVE-2024-42347 include unauthorized exposure of URLs in encrypted messages, compromising user privacy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203