Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39248

Опубликовано: 28 сент. 2022
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. matrix-android-sdk2 would then additionally sign such a key backup with its device key, spilling trust over to other devices trusting the matrix-android-sdk2 device. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. matrix-android-sdk2 version 1.5.1 has be

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:matrix:software_development_kit:*:*:*:*:*:android:*:*
Версия до 1.5.1 (исключая)

EPSS

Процентиль: 50%
0.00272
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.6
github
больше 3 лет назад

matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion

EPSS

Процентиль: 50%
0.00272
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-287