PT-2022-24804 · Unknown · Matrix-Appservice-Irc

CVE-2022-39203

·

Published

2022-09-13

·

Updated

2022-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions matrix-appservice-irc versions prior to 0.35.0
Description The issue allows attackers to specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the channel.
Recommendations For versions prior to 0.35.0, update to version 0.35.0 to resolve the issue. As a temporary workaround, operators may disable dynamic channel joining via dynamicChannels.enabled to prevent users from joining new channels.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39203
GHSA-XVQG-MV25-RWVW

Affected Products

Matrix-Appservice-Irc