Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39264

Опубликовано: 28 сент. 2022
Источник: nvd
CVSS3: 8.6
CVSS3: 5.9
EPSS Низкий

Описание

nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a workaround, one may apply the patch manually, avoid doing verifications of one's own devices, and/or avoid pressing the request button in the settings menu.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nheko-reborn:nheko:*:*:*:*:*:*:*:*
Версия до 0.10.2 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00363
Низкий

8.6 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 3 лет назад

nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a workaround, one may apply the patch manually, avoid doing verifications of one's own devices, and/or avoid pressing the request button in the settings menu.

CVSS3: 8.6
debian
больше 3 лет назад

nheko is a desktop client for the Matrix communication application. Al ...

EPSS

Процентиль: 58%
0.00363
Низкий

8.6 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-287