CVE-2023-38700 | matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the `matrixHandler.eventCacheSize` config value to `0`. This workaround may impact performance.
Conclusion & alert: CVE-2023-38700 is rated Low Risk (34.4/100): CVSS Low severity, with medium exploitation likelihood (EPSS 0.36%).Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2023-38700
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
GHSA-c7hh-3v6c-fj4q · Severity: low · Ecosystem: npm — matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
Affected software / configurations for CVE-2023-38700