Логотип exploitDog
bind:CVE-2022-39251
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39251

Количество 10

Количество 10

ubuntu логотип

CVE-2022-39251

больше 2 лет назад

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This at...

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2022-39251

больше 2 лет назад

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This at...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-39251

больше 2 лет назад

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This attac

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-39251

больше 2 лет назад

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-r48r-j8fx-mq2c

больше 2 лет назад

matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion

CVSS3: 8.6
EPSS: Низкий
rocky логотип

RLSA-2022:7190

больше 2 лет назад

Important: thunderbird security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7190

больше 2 лет назад

ELSA-2022-7190: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7184

больше 2 лет назад

ELSA-2022-7184: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7178

больше 2 лет назад

ELSA-2022-7178: thunderbird security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3800-1

больше 2 лет назад

Security update for MozillaThunderbird

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-39251

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This at...

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-39251

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This at...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-39251

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This attac

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-39251

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. ...

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-r48r-j8fx-mq2c

matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2022:7190

Important: thunderbird security update

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7190

ELSA-2022-7190: thunderbird security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7184

ELSA-2022-7184: thunderbird security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7178

ELSA-2022-7178: thunderbird security update (IMPORTANT)

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3800-1

Security update for MozillaThunderbird

больше 2 лет назад

Уязвимостей на страницу