Matrix Javascript SDK 34.3.0 Release Candidate 0

CPE Details

Matrix Javascript SDK 34.3.0 Release Candidate 0
34.3.0
2024-12-18
14h22 +00:00
2024-12-18
14h22 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:matrix:javascript_sdk:34.3.0:rc0:*:*:*:*:*:*

Informations

Vendor

matrix

Product

javascript_sdk

Version

34.3.0

Update

rc0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-42369 2024-08-20 14h37 +00:00 matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but also called by the 'leaveRoomChain()' method, so leaving a room will also trigger the bug. This was patched in matrix-js-sdk 34.3.1.
5.3
Moyen