Логотип exploitDog
bind:CVE-2022-39252
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39252

Количество 2

Количество 2

nvd логотип

CVE-2022-39252

больше 3 лет назад

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.6 fixes this issue.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-vp68-2wrm-69qm

больше 3 лет назад

matrix-sdk-crypto contains potential impersonation via room key forward responses

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-39252

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.6 fixes this issue.

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-vp68-2wrm-69qm

matrix-sdk-crypto contains potential impersonation via room key forward responses

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу