CVE-2023-28427
Summary
| CVE | CVE-2023-28427 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-28 21:15:00 UTC |
| Updated | 2023-05-30 06:16:00 UTC |
| Description | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Prototype pollution in matrix-js-sdk (part 2) · Advisory · matrix-org/matrix-js-sdk · GitHub |
MISC |
github.com |
|
| Debian -- Security Information -- DSA-5392-1 thunderbird |
MISC |
www.debian.org |
|
| Mozilla Thunderbird: Multiple Vulnerabilities (GLSA 202305-36) — Gentoo security |
MISC |
security.gentoo.org |
|
| Security releases: matrix-js-sdk 24.0.0 and matrix-react-sdk 3.69.0 | Matrix.org |
MISC |
matrix.org |
|
| [SECURITY] [DLA 3400-1] thunderbird security update |
MISC |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160550 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-1802)
- 160552 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-1806)
- 160555 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-1809)
- 181749 Debian Security Update for thunderbird (DSA 5392-1)
- 181752 Debian Security Update for thunderbird (DLA 3400-1)
- 184392 Debian Security Update for thunderbird (CVE-2023-28427)
- 241350 Red Hat Update for thunderbird (RHSA-2023:1802)
- 241351 Red Hat Update for thunderbird (RHSA-2023:1811)
- 241352 Red Hat Update for thunderbird (RHSA-2023:1810)
- 241353 Red Hat Update for thunderbird (RHSA-2023:1804)
- 241354 Red Hat Update for thunderbird (RHSA-2023:1806)
- 241355 Red Hat Update for thunderbird (RHSA-2023:1809)
- 241621 Red Hat Update for thunderbird (RHSA-2023:1803)
- 241645 Red Hat Update for thunderbird (RHSA-2023:1805)
- 257235 CentOS Security Update for thunderbird (CESA-2023:1806)
- 378242 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2023-12)
- 502947 Alpine Linux Security Update for riot-web
- 503174 Alpine Linux Security Update for element-web
- 506034 Alpine Linux Security Update for element-web
- 691101 Free Berkeley Software Distribution (FreeBSD) Security Update for matrix clients (5b0ae405-cdc7-11ed-bb39-901b0e9408dc)
- 710735 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202305-36)
- 940981 AlmaLinux Security Update for thunderbird (ALSA-2023:1802)
- 940986 AlmaLinux Security Update for thunderbird (ALSA-2023:1809)
- 960919 Rocky Linux Security Update for thunderbird (RLSA-2023:1809)
- 960920 Rocky Linux Security Update for thunderbird (RLSA-2023:1802)