Vulnerabilities (CVE)

Filtered by vendor Matrix Subscribe
Filtered by product Matrix Irc Bridge
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38700 1 Matrix 1 Matrix Irc Bridge 2023-08-11 N/A 3.7 LOW
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the `matrixHandler.eventCacheSize` config value to `0`. This workaround may impact performance.