CVE-2022-39252

MEDIUM6.5EPSS 0.16%

matrix-sdk Impersonation of room keys

發布日:2022/9/30修改日:2023/11/8
也稱為:GHSA-vp68-2wrm-69qmRUSTSEC-2022-0085

描述

When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

參考連結(8)