Matrix / Javascript Sdk
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-42369 | A room with itself as a its predecessor will freeze matrix-js-sdk | MEDIUM | 5.1 | Aug 20, 2024 |
| CVE-2023-29529 | matrix-js-sdk vulnerable to invisible eavesdropping in group calls | MEDIUM | 5.3 | Apr 14, 2023 |
| CVE-2023-28427 | Prototype pollution in matrix-js-sdk | HIGH | 8.2 | Mar 28, 2023 |
| CVE-2022-36059 | Prototype pollution in matrix-js-sdk | HIGH | 8.2 | Mar 28, 2023 |
| CVE-2022-39250 | Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification | HIGH | 8.6 | Sep 29, 2022 |
| CVE-2022-39251 | Matrix Javascript SDK vulnerable to Olm/Megolm protocol confusion | HIGH | 8.6 | Sep 28, 2022 |
| CVE-2022-39249 | Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessions | HIGH | 7.5 | Sep 28, 2022 |
| CVE-2022-39236 | Matrix Javascript SDK improper beacon events can cause availability issues | MEDIUM | 5.3 | Sep 28, 2022 |
| CVE-2021-44538 | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel b… | CRITICAL | 9.8 | Dec 14, 2021 |
| CVE-2021-40823 | A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in… | MEDIUM | 5.9 | Sep 13, 2021 |
Showing 1 to 10 of 10 CVEs