Junglewise Threat Intelligence

CVE-2023-38691: Matrix AppService Bridge OpenID token subject verification bypass

CVE-2023-38691 · Severity: low · CVSS 3.1 · Published 2023-08-04

Vendors: Matrix.org.

Executive brief

Matrix AppService Bridge is a library used to connect third-party applications and services to the Matrix communication protocol. A flaw in OpenID token validation allows a malicious Matrix server to impersonate any user and gain unauthorized access to provisioning APIs, potentially enabling account takeover or unauthorized modifications in connected services.

Technical details

The vulnerability is an improper authentication flaw (CWE-287) in the OpenID token exchange mechanism. The library fails to verify that the servername portion of the OpenID 'sub' parameter (which contains the user's claimed MXID) matches the servername of the Matrix server handling the exchange. An attacker controlling a malicious Matrix server can craft an OpenID response with a forged 'sub' parameter impersonating any user and use the resulting token to make unauthorized provisioning API calls. The attack requires the provisioning API to be enabled and network access to the vulnerable bridge; exploitation requires low privileges (authentication to the attacker-controlled Matrix server). Patches are available in versions 8.1.2 and 9.0.1 or later.

Affected products

  • Matrix.org AppService Bridge 4.0.0 through 9.0.0 (fixed in 8.1.2 and 9.0.1+)

Timeline

  • 2023-08-04: disclosed
  • 2023-08-04: patched

References