Junglewise Threat Intelligence

CVE-2024-47824: Matrix React SDK information disclosure on room invitation

CVE-2024-47824 · Severity: low · CVSS 3.1 · Published 2024-10-15

Technologies: matrix-react-sdk (npm), Matrix.org React SDK. Vendors: npm, Matrix.org.

Executive brief

Matrix React SDK is a JavaScript library used by web-based chat applications (like Element) to implement end-to-end encryption and messaging. A malicious chat server can trick the application into sharing historical message decryption keys when a user invites another person to a room, allowing the server to decrypt previously protected messages. This undermines the confidentiality of encrypted conversations and could expose sensitive communication history.

Technical details

The vulnerability is an information disclosure flaw (CWE-200) in matrix-react-sdk versions 3.18.0 through 3.101.x that occurs when a user invites another user to a room. The root cause is improper reuse of the MatrixClient.sendSharedHistoryKeys function, which was designed to share historical message keys but is inherently vulnerable to attack by a malicious homeserver. A malicious homeserver can inject specially crafted devices to intercept and capture these shared encryption keys. The attack requires network access to the homeserver and occurs automatically during the room invitation workflow—no additional user interaction is needed. An attacker can thus gain access to decrypt historical messages in the invited room. The vulnerability was patched in version 3.102.0 by removing calls to the vulnerable key-sharing functionality.

Affected products

  • Matrix.org React SDK 3.18.0 through 3.101.x

Timeline

  • 2024-10-15: disclosed
  • 2024-10-15: patched: Version 3.102.0

References

Related threats