Количество 2
Количество 2
CVE-2022-39252
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.6 fixes this issue.
GHSA-vp68-2wrm-69qm
matrix-sdk-crypto contains potential impersonation via room key forward responses
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-39252 matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.6 fixes this issue. | CVSS3: 8.6 | 0% Низкий | больше 3 лет назад | |
GHSA-vp68-2wrm-69qm matrix-sdk-crypto contains potential impersonation via room key forward responses | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу