Vulnerabilities/

Matrix IRC Bridge truncated content of messages can be leaked

Severity:
Medium

Description

The matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID they don’t have access to.

Recommendation

Update the matrix-appservice-irc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-appservice-irc
Anything's wrong? Let us know Last updated on April 15, 2024

This issue is available in SmartScanner Professional

See Pricing