CVE-2023-38691 is a medium-severity vulnerability affecting matrix-appservice-bridge versions 4.0.0 through 8.1.1 and 9.0.0. A malicious Matrix server can impersonate users via the provisioning API by manipulating the OpenID exchange, specifically by providing a false servername in the 'sub' parameter. This allows an attacker to perform provisioning requests on behalf of other users, leading to a high impact on confidentiality. The vulnerability has a CVSS score of 6.5, indicating a network attack vector with low complexity and no user interaction required. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 8.1.2CPE matchmatch criteria | cpe:2.3:a:matrix:matrix-appservice-bridge:*:*:*:*:*:node.js:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:matrix:matrix-appservice-bridge:9.0.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
Aug 4, 2023matrix-appservice-bridge doesn't verify the sub parameter of an openId token exchange
Jul 26, 2023Multiple High Severity Vulnerabilities in Matrix Bridges
Jul 12, 2023Security Updates for Matrix Bridges: OpenID Token Exchange, IRC Command Injection, and Message Leak Vulnerabilities
Jul 10, 2023