Matrix Javascript SDK 24.1.0 Release Candidate 1 for Node.js

CPE Details

Matrix Javascript SDK 24.1.0 Release Candidate 1 for Node.js
24.1.0
2023-04-20
16h00 +00:00
2023-08-11
21h44 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:matrix:javascript_sdk:24.1.0:rc1:*:*:*:node.js:*:*

Informations

Vendor

matrix

Product

javascript_sdk

Version

24.1.0

Update

rc1

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-42369 2024-08-20 14h37 +00:00 matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but also called by the 'leaveRoomChain()' method, so leaving a room will also trigger the bug. This was patched in matrix-js-sdk 34.3.1.
5.3
Medium