Matrix Irc Bridge Matrix Irc Bridge

Do you want an email whenever new security vulnerabilities are reported in Matrix Irc Bridge?

By the Year

In 2024 there have been 0 vulnerabilities in Matrix Irc Bridge . Last year Matrix Irc Bridge had 2 security vulnerabilities published. Right now, Matrix Irc Bridge is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 2 6.75
2022 4 7.38
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Matrix Irc Bridge vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Matrix Irc Bridge Security Vulnerabilities

matrix-appservice-irc is a Node.js IRC bridge for Matrix

CVE-2023-38700 3.7 - Low - August 04, 2023

matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the `matrixHandler.eventCacheSize` config value to `0`. This workaround may impact performance.

matrix-appservice-irc is a Node.js IRC bridge for Matrix

CVE-2023-38690 9.8 - Critical - August 04, 2023

matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge bot. Versions 1.0.1 and above are patched. There are no robust workarounds to the bug. One may disable dynamic channels in the config to disable the most common execution method but others may exist.

Improper Input Validation

A vulnerability was found in matrix-appservice-irc up to 0.35.1

CVE-2022-3971 5.6 - Medium - November 13, 2022

A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version 0.36.0 is able to address this issue. The name of the patch is 179313a37f06b298150edba3e2b0e5a73c1415e7. It is recommended to upgrade the affected component. VDB-213550 is the identifier assigned to this vulnerability.

SQL Injection

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix

CVE-2022-39203 8.8 - High - September 13, 2022

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the channel. The vulnerability has been patched in matrix-appservice-irc 0.35.0. As a workaround operators may disable dynamic channel joining via `dynamicChannels.enabled` to prevent users from joining new channels, which prevents any new channels being bridged outside of what is already bridged, and what is specified in the config.

Improper Privilege Management

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix

CVE-2022-39202 6.3 - Medium - September 13, 2022

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc perform parsing of such modes incorrectly, potentially resulting in the wrong user being given permissions. Mode commands can only be executed by privileged users, so this can only be abused if an operator is tricked into running the command on behalf of an attacker. The vulnerability has been patched in matrix-appservice-irc 0.35.0. As a workaround users should refrain from entering mode commands suggested by untrusted users. Avoid using multiple modes in a single command.

Improper Privilege Management

matrix-appservice-irc is a Node.js IRC bridge for Matrix

CVE-2022-29166 8.8 - High - May 05, 2022

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc 0.33.2. Refrain from replying to messages from untrusted participants in IRC-bridged Matrix rooms. There are no known workarounds for this issue.

Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Matrix Irc Bridge or by Matrix? Click the Watch button to subscribe.

Matrix
Vendor

subscribe