Логотип exploitDog
bind:CVE-2022-39254
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39254

Количество 4

Количество 4

ubuntu логотип

CVE-2022-39254

больше 3 лет назад

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-39254

больше 3 лет назад

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-39254

больше 3 лет назад

matrix-nio is a Python Matrix client library, designed according to sa ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-w4pr-4vjg-hffh

больше 3 лет назад

When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-39254

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-39254

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-39254

matrix-nio is a Python Matrix client library, designed according to sa ...

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w4pr-4vjg-hffh

When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder

CVSS3: 8.6
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу