VDB
Sign up
MEDIUM6.5

GHSA-35g4-qx3c-vjhx

Automatic room upgrade handling can be used maliciously to bridge a room non-consentually

Quick fix

GHSA-35g4-qx3c-vjhx — matrix-appservice-bridge: upgrade to the fixed version with the command below.

npm install matrix-appservice-bridge@2.6.1

Details

### Impact

If a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge` instance.), any `m.room.tombstone` event it encounters will be used to unbridge the current room and bridge into the target room. However, the target room `m.room.create` event is not checked to verify if the `predecessor` field contains the previous room. This means that any mailcious admin of a bridged room can repoint the traffic to a different room without the new room being aware.

### Patches

Versions 2.6.1 and greater are patched.

### Workarounds

Disabling the automatic room upgrade handling can be done by removing the `roomUpgradeOpts` key from the `Bridge` class options.

### References

The issue is patched by https://github.com/matrix-org/matrix-appservice-bridge/pull/330

### For more information]

If you have any questions or comments about this advisory, email us at security@matrix.org.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/matrix-appservice-bridge
Introduced in: 0Fixed in: 2.6.1
Fixnpm install matrix-appservice-bridge@2.6.1

References