Matrix SDK for React's URL preview setting for a room is controllable by the homeserver
Moderate severity
GitHub Reviewed
Published
Aug 6, 2024
in
matrix-org/matrix-react-sdk
•
Updated Aug 8, 2024
Description
Published to the GitHub Advisory Database
Aug 6, 2024
Reviewed
Aug 6, 2024
Published by the National Vulnerability Database
Aug 6, 2024
Last updated
Aug 8, 2024
Impact
A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server.
Even if the CVSS score would be 4.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N) the maintainer classifies this as High severity issue.
Patches
This was patched in matrix-react-sdk 3.105.1.
Workarounds
Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected.
References
N/A.
References