A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but also called by the 'leaveRoomChain()' method, so leaving a room will also trigger the bug.
Even if the CVSS score would be 4.1 (AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L) we classify this as High severity issue.
This was patched in matrix-js-sdk 34.3.1.
Sanity check rooms before passing them to the matrix-js-sdk or avoid calling either getRoomUpgradeHistory or leaveRoomChain.
N/A.
| Score | Percentile |
|---|---|
| 0.21% | 42.52% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 4.1 | 3.1 | — |
|
| 5.1 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-vhr5-g3pm-49fm ↗ |
| CVE | CVE-2024-42369 ↗ |
| CWE id | Name |
|---|---|
| CWE-674 | Uncontrolled Recursion |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | matrix-js-sdk | < 34.3.1 | 34.3.1 | — |