It was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target.
Please upgrade to 1.0.1.
You can set the matrixHandler.eventCacheSize config value to 0 to workaround this bug. However, this may impact performance.
Discovered and reported by Val Lorentz.
If you have any questions or comments about this advisory email us at security@matrix.org.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-200"
],
"github_reviewed_at": "2023-08-04T17:26:07Z",
"nvd_published_at": "2023-08-04T19:15:09Z",
"severity": "LOW"
}