Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjmc-4p83-pp26

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Logic error in Matrix SDK for Android

A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 leads to a situation where identity verification is inadequate and thus a key-requesting device can be impersonated.

Пакеты

Наименование

org.matrix.android:matrix-android-sdk2

maven
Затронутые версииВерсия исправления

< 1.2.2

1.2.2

EPSS

Процентиль: 47%
0.00239
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 5.9
nvd
больше 4 лет назад

A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the attacker to decrypt end-to-end encrypted messages sent by affected clients.

EPSS

Процентиль: 47%
0.00239
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-327