Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-39254

Опубликовано: 29 сент. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 8.6

Описание

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.

РелизСтатусПримечание
bionic

DNE

devel

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

needs-triage

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
больше 3 лет назад

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.

CVSS3: 8.6
debian
больше 3 лет назад

matrix-nio is a Python Matrix client library, designed according to sa ...

CVSS3: 8.6
github
больше 3 лет назад

When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder

8.6 High

CVSS3