Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2268 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the `matrixHandler.eventCacheSize` config value to `0`. This workaround may impact performance. |
Github GHSA |
GHSA-c7hh-3v6c-fj4q | matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms |
Thu, 03 Oct 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-03T18:08:51.929Z
Reserved: 2023-07-24T16:19:28.365Z
Link: CVE-2023-38700
Updated: 2024-08-02T17:46:56.508Z
Status : Modified
Published: 2023-08-04T19:15:09.697
Modified: 2024-11-21T08:14:05.010
Link: CVE-2023-38700
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA