FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-12-18 00:09:58 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
ab4e6f65-a142-11ef-84e9-901b0e9408dcelement-web -- several vulnerabilities

Element team reports:

Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked.

A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them.


Discovery 2024-11-12
Entry 2024-11-12
element-web
< 1.11.85

CVE-2024-51749
CVE-2024-51750
https://github.com/element-hq/element-web/security/advisories/GHSA-5486-384g-mcx2
https://github.com/element-hq/element-web/security/advisories/GHSA-w36j-v56h-q9pc
574f7bc9-a141-11ef-84e9-901b0e9408dcMatrix clients -- mxc uri validation in js sdk

matrix-js-sdk upstream reports:

matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver.


Discovery 2024-11-12
Entry 2024-11-12
cinny
< 4.2.3

element-web
< 1.11.85

CVE-2024-50336
https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-xvg8-m4x3-w6xr