Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2431 | matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected versions an attacker could upload a malicious piece of media to the media repo, which would then be served with `Content-Disposition: inline` upon download. This vulnerability could be leveraged to execute scripts embedded in SVG content. Commits `77ec235` and `bf8abdd` fix the issue and are included in the 1.3.0 release. Operators should upgrade to v1.3.0 as soon as possible. Operators unable to upgrade should override the `Content-Disposition` header returned by matrix-media-repo as a workaround. |
Github GHSA |
GHSA-5crw-6j7v-xc72 | matrix-media-repo: Unsafe media served inline on download endpoints |
Thu, 26 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-26T14:03:33.058Z
Reserved: 2023-08-28T16:56:43.365Z
Link: CVE-2023-41318
Updated: 2024-08-02T18:54:05.034Z
Status : Modified
Published: 2023-09-08T20:15:14.693
Modified: 2024-11-21T08:21:03.657
Link: CVE-2023-41318
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA