GHSA-52mq-6jcv-j79x

Suggest an improvement
Source
https://github.com/advisories/GHSA-52mq-6jcv-j79x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-52mq-6jcv-j79x/GHSA-52mq-6jcv-j79x.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-52mq-6jcv-j79x
Aliases
Related
Published
2021-03-03T02:23:56Z
Modified
2023-11-01T04:54:11.828245Z
Severity
  • 2.6 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
User content sandbox can be confused into opening arbitrary documents
Details

Impact

The user content sandbox can be abused to trick users into opening unexpected documents after several user interactions. The content can be opened with a blob origin from the Matrix client, so it is possible for a malicious document to access user messages and secrets.

Patches

This has been fixed by https://github.com/matrix-org/matrix-react-sdk/pull/5657, which is included in 3.15.0.

Workarounds

There are no known workarounds.

Database specific
{
    "nvd_published_at": "2021-03-02T03:15:00Z",
    "github_reviewed_at": "2021-03-02T02:47:04Z",
    "severity": "LOW",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-345"
    ]
}
References

Affected packages

npm / matrix-react-sdk

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.15.0