| id: GO-2023-2053 |
| modules: |
| - module: github.com/turt2live/matrix-media-repo |
| versions: |
| - fixed: 1.3.0 |
| vulnerable_at: 1.2.13 |
| summary: 'matrix-media-repo: Unsafe media served inline on download endpoints in github.com/turt2live/matrix-media-repo' |
| cves: |
| - CVE-2023-41318 |
| ghsas: |
| - GHSA-5crw-6j7v-xc72 |
| references: |
| - advisory: https://github.com/turt2live/matrix-media-repo/security/advisories/GHSA-5crw-6j7v-xc72 |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-41318 |
| - fix: https://github.com/turt2live/matrix-media-repo/commit/77ec2354e8f46d5ef149d1dcaf25f51c04149137 |
| - fix: https://github.com/turt2live/matrix-media-repo/commit/bf8abdd7a5371118e280c65a8e0ec2b2e9bdaf59 |
| - web: https://developer.mozilla.org/en-US/docs/Web/SVG/Element/script |
| source: |
| id: GHSA-5crw-6j7v-xc72 |
| created: 2024-08-20T12:02:14.150432-04:00 |
| review_status: UNREVIEWED |
| unexcluded: EFFECTIVELY_PRIVATE |