CVE-2025-48937
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
4.9
MEDIUM
CVSS 3.1
EPSS 0.31%
描述
matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High severity security issue.
如何修補 CVE-2025-48937
要修補 CVE-2025-48937,請將受影響套件升級到下列已修補版本。
- —升級至 0.11.1 或更新版本
- —升級至 0.11.1 或更新版本
CVE-2025-48937 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 0.8.0, < 0.11.1
- >= 0.8.0, < 0.11.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.9 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |