Junglewise Threat Intelligence

CVE-2022-3971: Matrix-appservice-irc SQL injection via roomIds argument

CVE-2022-3971 · Severity: low · CVSS 3.1 · Published 2022-11-13

Technologies: Matrix.org Appservice IRC, matrix-appservice-irc (npm). Vendors: Matrix.org, npm.

Executive brief

Matrix-appservice-irc is a bridge component that allows Matrix chat users to communicate with IRC networks. A SQL injection vulnerability in the roomIds parameter could allow an attacker with control over room mappings to manipulate database queries, potentially exposing or corrupting chat data stored in the PostgreSQL backend.

Technical details

The vulnerability is a SQL injection flaw (CWE-89) in src/datastore/postgres/PgDataStore.ts affecting how the roomIds argument is processed when checking room visibility. An attacker who can set malicious Matrix IDs in room mappings can inject SQL commands into database queries. The attack requires administrative control over room configuration; it is not remotely exploitable by unauthenticated users. Successful exploitation could lead to unauthorized data disclosure or modification of the database. The issue was fixed in version 0.36.0 via patch 179313a37f06b298150edba3e2b0e5a73c1415e7.

Affected products

  • Matrix.org matrix-appservice-irc prior to 0.36.0

Timeline

  • 2022-11-13: disclosed
  • 2022-11-15: patched: Patch merged in PR #1619; fixed in version 0.36.0

References

Related threats