CVE-2024-47779 - CVE House
Back to Database
Status published High CVE-2024-47779

Element Web vulnerable to potential exposure of access token via authenticated media

Vulnerability Description

Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Note that despite superficial similarity to CVE-2024-47771, this is an entirely separate vulnerability, caused by a separate piece of code included only in Element Web. Element Web and Element Desktop share most but not all, of their code and this vulnerability exists in the part of the code base which is not shared between the projects. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47779

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

element-web
Vulnerable Versions:
>= 1.11.70, < 1.11.81

Timeline

Official Publish: October 15th, 2024
Last Modified: November 12th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)