CVE-2022-39254
Summary
| CVE | CVE-2022-39254 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-29 15:15:00 UTC |
| Updated | 2023-07-13 17:24:00 UTC |
| Description | matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Matrix-nio Project | Matrix-nio | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| When receiving forwarded room keys, we don't check that the forwarder device matches the device we requested from · Advisory · poljar/matrix-nio · GitHub | CONFIRM | github.com | |
| fix(crypto): Only accept forwarded room keys from our own trusted dev… · poljar/matrix-nio@b1cbf23 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184061 Debian Security Update for python-matrix-nio (CVE-2022-39254)