Vulnerabilities in matrix-org

83 results
Vexday analysis

O ecossistema matrix-org acumula 80 CVEs catalogadas, com 2 classificadas como críticas e nenhuma atualmente registrada no catálogo CISA KEV, posicionando o vendor abaixo da média geral de exploração ativa do catálogo. A ausência de provas de conceito públicas e de novos registros nos últimos 90 dias sugere um ritmo de descoberta baixo no período recente, embora o histórico acumulado mereça acompanhamento contínuo. A falha mais prevalente é do tipo CWE-287 (falhas de autenticação), o que indica uma área estrutural de risco que equipes de segurança devem priorizar em revisões de configuração e controle de acesso. A CVE mais perigosa ativa no momento é CVE-2020-26257, com score EPSS de 0,0236, sinalizando probabilidade de exploração relativamente baixa, mas que não deve ser descartada em ambientes que ainda não aplicaram as correções correspondentes.

CVE-2023-28103HIGHPrototype pollution in matrix-react-sdkEPSS 0.7%CVE-2022-39202MEDIUMIRC mode parameter confusion in matrix-appservice-ircEPSS 0.7%CVE-2022-39246HIGHmatrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessionsEPSS 0.7%CVE-2024-47080HIGHmatrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeserverEPSS 0.7%CVE-2022-36009MEDIUMIncorrect parsing of access level in gomatrixserverlib and dendriteEPSS 0.7%CVE-2024-47824HIGHMalicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a roomEPSS 0.7%CVE-2023-42453LOWImproper validation of receipts allows forged read receipts in matrix synapseEPSS 0.7%CVE-2022-39335MEDIUMSynapse does not apply enough checks to servers requesting auth events of events in a roomEPSS 0.6%CVE-2023-30609MEDIUMmatrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlightingEPSS 0.6%CVE-2023-32683LOWURL deny list bypass via oEmbed and image URLs when generating previews in SynapseEPSS 0.6%CVE-2023-38700LOWmatrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged roomsEPSS 0.6%CVE-2025-24024CRITICALMjolnir v1.9.0 accepts commands from any roomEPSS 0.6%CVE-2023-29529MEDIUMmatrix-js-sdk vulnerable to invisible eavesdropping in group callsEPSS 0.5%CVE-2022-39252HIGHWhen matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwarderEPSS 0.5%CVE-2024-39691MEDIUMMalicious Matrix homeserver can leak truncated message content of messages it shouldn't have access toEPSS 0.5%CVE-2024-42369MEDIUMA room with itself as a its predecessor will freeze matrix-js-sdkEPSS 0.5%CVE-2024-52813MEDIUMmatrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identityEPSS 0.5%CVE-2023-38691MEDIUMmatrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIsEPSS 0.5%CVE-2023-37259MEDIUMCross site scripting in Export Chat featureEPSS 0.5%CVE-2024-32000MEDIUMTruncated content of messages can be leaked from matrix-appservice-ircEPSS 0.4%