Описание
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.6 fixes this issue.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.6 (исключая)
cpe:2.3:a:matrix:matrix-rust-sdk:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00227
Низкий
8.6 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
matrix-sdk-crypto contains potential impersonation via room key forward responses
EPSS
Процентиль: 45%
0.00227
Низкий
8.6 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-287