Junglewise Threat Intelligence

CVE-2024-42347: Matrix SDK for React URL preview bypass in encrypted rooms

CVE-2024-42347 · Severity: low · CVSS 3.1 · Published 2024-08-06

Technologies: The Matrix.org Foundation Matrix-React-Sdk. Vendors: npm.

Executive brief

Matrix SDK for React is a client library for the Matrix communication protocol. A malicious homeserver can manipulate a user's settings to force URL previews to be enabled in encrypted rooms, causing encrypted message URLs to be exposed to the server in plain text. This defeats the encryption protection users expect and leaks metadata about their communications.

Technical details

The vulnerability exists in how matrix-react-sdk handles the URL preview setting for rooms. A malicious or compromised homeserver can modify a user's account data to enable URL previews in end-to-end encrypted rooms without the user's consent or awareness. When URL previews are enabled, any URLs contained in encrypted messages are sent to the homeserver to generate previews, leaking metadata that should remain protected by encryption. The attack requires a malicious or compromised homeserver (high privilege), but no user interaction. The issue was patched in version 3.105.1 by restricting the homeserver's ability to control this security-critical setting.

Affected products

  • The Matrix.org Foundation matrix-react-sdk <3.105.1

Timeline

  • 2024-08-06: disclosed: CVE-2024-42347 published
  • 2024-08-06: patched: Fix released in version 3.105.1

References

Related threats