VDB
CVE-2022-36060
CVE-2022-36060
PUBLISHED
CVSS 8.199999809265137 HIGH
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered. This issue has been fixed in matrix-react-sdk 3.53.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.
EPSS 0.21% · 43.7th percentile
Risk Scores
CVSS v3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS Score
0.21%
43.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| matrix-org | matrix-react-sdk | * |
| npm | matrix-react-sdk | 0 |
| matrix | react_sdk | 0 |
Timeline
- Mar 28, 2023 CVE Published
- Mar 29, 2023 EPSS Score
- May 6, 2023 EPSS Score
- Jun 13, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
- Aug 29, 2023 EPSS Score
- Oct 6, 2023 EPSS Score
- Nov 7, 2023 CVE Updated
- Nov 13, 2023 EPSS Score
- Dec 21, 2023 EPSS Score
- Jan 28, 2024 EPSS Score
- Mar 6, 2024 EPSS Score