CVE-2022-39203

Improper Privilege Management in npm/matrix-appservice-irc

Identifiers

GHSA-xvqg-mv25-rwvw, CVE-2022-39203

Package Slug

npm/matrix-appservice-irc

Vulnerability

Improper Privilege Management

Description

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the channel. The vulnerability has been patched in matrix-appservice-irc 0.35.0. As a workaround operators may disable dynamic channel joining via dynamicChannels.enabled to prevent users from joining new channels, which prevents any new channels being bridged outside of what is already bridged, and what is specified in the config.

Affected Versions

All versions before 0.35.0

Solution

Upgrade to version 0.35.0 or above.

Last Modified

2022-09-15

source