It was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target.
Please upgrade to 1.0.1.
You can set the matrixHandler.eventCacheSize
config value to 0
to workaround this bug. However, this may impact performance.
Discovered and reported by Val Lorentz.
If you have any questions or comments about this advisory email us at security@matrix.org.
{ "nvd_published_at": "2023-08-04T19:15:09Z", "cwe_ids": [ "CWE-200" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-08-04T17:26:07Z" }