CVE-2023-38700

matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the `matrixHandler.eventCacheSize` config value to `0`. This workaround may impact performance.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:*

History

11 Aug 2023, 18:58

Type Values Removed Values Added
First Time Matrix matrix Irc Bridge
CPE cpe:2.3:a:matrix:matrix-appservice-irc:*:*:*:*:*:node.js:*:* cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:*

10 Aug 2023, 13:48

Type Values Removed Values Added
CWE CWE-200 NVD-CWE-noinfo
CPE cpe:2.3:a:matrix:matrix-appservice-irc:*:*:*:*:*:node.js:*:*
First Time Matrix matrix-appservice-irc
Matrix
References (MISC) https://github.com/matrix-org/matrix-appservice-irc/releases/tag/1.0.1 - (MISC) https://github.com/matrix-org/matrix-appservice-irc/releases/tag/1.0.1 - Release Notes
References (MISC) https://github.com/matrix-org/matrix-appservice-irc/security/advisories/GHSA-c7hh-3v6c-fj4q - (MISC) https://github.com/matrix-org/matrix-appservice-irc/security/advisories/GHSA-c7hh-3v6c-fj4q - Vendor Advisory
References (MISC) https://github.com/matrix-org/matrix-appservice-irc/commit/8bbd2b69a16cbcbeffdd9b5c973fd89d61498d75 - (MISC) https://github.com/matrix-org/matrix-appservice-irc/commit/8bbd2b69a16cbcbeffdd9b5c973fd89d61498d75 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.7

04 Aug 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-04 19:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-38700

Mitre link : CVE-2023-38700

CVE.ORG link : CVE-2023-38700


JSON object : View

Products Affected

matrix

  • matrix_irc_bridge
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor