CVE-2022-36059 is a medium-severity vulnerability affecting the matrix-js-sdk, a JavaScript client-server SDK for the Matrix messaging protocol, in versions prior to 19.4.0. This flaw allows specially crafted events to temporarily disrupt or impede the SDK's functionality, potentially leading to data exclusion or corruption without immediately apparent errors. The vulnerability has a CVSS score of 5.3, indicating a network-based attack with low complexity and no user interaction required, primarily impacting data integrity (CWE-1321). There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 19.4.0CPE matchmatch criteria | cpe:2.3:a:matrix:javascript_sdk:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Previously Disclosed Prototype Pollution Vulnerabilities in matrix-js-sdk and matrix-react-sdk
Mar 29, 2023Prototype Pollution in matrix-js-sdk (previously announced)
Mar 29, 2023High-severity Prototype Pollution vulnerabilities in matrix-js-sdk and matrix-react-sdk
Mar 29, 2023matrix-js-sdk Prototype Pollution vulnerability
Mar 28, 2023Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack
Aug 31, 2022