Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39252

Опубликовано: 29 сент. 2022
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.6 fixes this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:matrix:matrix-rust-sdk:*:*:*:*:*:*:*:*
Версия до 0.6 (исключая)

EPSS

Процентиль: 45%
0.00227
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

matrix-sdk-crypto contains potential impersonation via room key forward responses

EPSS

Процентиль: 45%
0.00227
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-287