CVE-2024-51750

Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
Configurations

No configuration.

History

13 Nov 2024, 17:01

Type Values Removed Values Added
Summary
  • (es) Element es un cliente web de Matrix creado con el SDK de Matrix React. Un servidor doméstico malintencionado puede enviar mensajes no válidos a través de la federación, lo que puede impedir que Element Web and Desktop muestre mensajes individuales o toda la sala que los contiene. Esto se solucionó en Element Web and Desktop 1.11.85.

12 Nov 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-12 17:15

Updated : 2024-11-13 17:01


NVD link : CVE-2024-51750

Mitre link : CVE-2024-51750

CVE.ORG link : CVE-2024-51750


JSON object : View

Products Affected

No product.

CWE
CWE-248

Uncaught Exception