Vulnerabilities/

matrix-js-sdk vulnerable to invisible eavesdropping in group calls

Severity:
Medium

Description

An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call.

Recommendation

Update the matrix-js-sdk package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-js-sdk
Anything's wrong? Let us know Last updated on April 25, 2023

This issue is available in SmartScanner Professional

See Pricing