blob: b492778edb0ff384914810a7002f6d3ad4ad28e9 [file] [log] [blame]
id: GO-2023-2053
modules:
- module: github.com/turt2live/matrix-media-repo
versions:
- fixed: 1.3.0
vulnerable_at: 1.2.13
summary: 'matrix-media-repo: Unsafe media served inline on download endpoints in github.com/turt2live/matrix-media-repo'
cves:
- CVE-2023-41318
ghsas:
- GHSA-5crw-6j7v-xc72
references:
- advisory: https://github.com/turt2live/matrix-media-repo/security/advisories/GHSA-5crw-6j7v-xc72
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-41318
- fix: https://github.com/turt2live/matrix-media-repo/commit/77ec2354e8f46d5ef149d1dcaf25f51c04149137
- fix: https://github.com/turt2live/matrix-media-repo/commit/bf8abdd7a5371118e280c65a8e0ec2b2e9bdaf59
- web: https://developer.mozilla.org/en-US/docs/Web/SVG/Element/script
source:
id: GHSA-5crw-6j7v-xc72
created: 2024-08-20T12:02:14.150432-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE