Matrix Mjolnir
cpe:2.3:a:mjolnir_project:mjolnir:*:*:*:*:*:*:*
- 1.9.0
A vulnerability in the Mjolnir moderation tool for Matrix, specifically in version 1.9.0, allows the bot to respond to management commands from any room it is a member of. This issue can enable users who are not bot operators to access the bot's functions, including server administration components if activated. The vulnerability arises from a feature that improperly manages command responses based on room membership.
Exploitation of this vulnerability could lead to unauthorized users executing management commands through the bot, potentially allowing them to perform administrative tasks on the server.
To reproduce this vulnerability, invite the Mjolnir bot to a room and have a non-operator user send a management command. The bot will respond to the command, demonstrating the unauthorized access.
Users can upgrade to Mjolnir version 1.9.1 or 1.9.2, which address the vulnerability. If an upgrade is not possible, downgrading to version 1.8.3 is recommended.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.