Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjv9-6jwc-5g68

Опубликовано: 13 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.

SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.

EPSS

Процентиль: 37%
0.00159
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.

EPSS

Процентиль: 37%
0.00159
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327