Skip to content

A malicious homeserver can modify events leading to unrenderable events or rooms

High
davidegirardi published GHSA-w36j-v56h-q9pc Nov 12, 2024

Package

Element Web

Affected versions

< 1.11.85

Patched versions

1.11.85

Description

Impact

A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them.

Even if the CVSS score would be 5.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L) we classify this as High severity issue.

Patches

This was patched in Element Web and Desktop 1.11.85.

Workarounds

None.

References

N/A.

Severity

High

CVE ID

CVE-2024-51750

Weaknesses