{"api_version":"1","generated_at":"2026-07-23T22:22:34+00:00","cve":"CVE-2021-40823","urls":{"html":"https://cve.report/CVE-2021-40823","api":"https://cve.report/api/cve/CVE-2021-40823.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-40823","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-40823"},"summary":{"title":"CVE-2021-40823","description":"A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the homeserver to decrypt end-to-end encrypted messages sent by affected clients.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-09-13 19:15:00","updated_at":"2023-08-08 14:22:00"},"problem_types":["CWE-290"],"metrics":[],"references":[{"url":"https://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing","name":"https://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing","refsource":"MISC","tags":[],"title":"Disclosing CVE-2021-40823 and CVE-2021-40824: E2EE vulnerability in multiple Matrix clients | Matrix.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/matrix-org/matrix-js-sdk/releases/tag/v12.4.1","name":"https://github.com/matrix-org/matrix-js-sdk/releases/tag/v12.4.1","refsource":"MISC","tags":[],"title":"Release v12.4.1 · matrix-org/matrix-js-sdk · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-40823","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40823","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"40823","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"matrix","cpe5":"javascript_sdk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-40823","qid":"501918","title":"Alpine Linux Security Update for riot-web"},{"cve":"CVE-2021-40823","qid":"503178","title":"Alpine Linux Security Update for element-web"},{"cve":"CVE-2021-40823","qid":"506038","title":"Alpine Linux Security Update for element-web"},{"cve":"CVE-2021-40823","qid":"690038","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for matrix clients (93eb0e48-14ba-11ec-875e-901b0e9408dc)"},{"cve":"CVE-2021-40823","qid":"980380","title":"Nodejs (npm) Security Update for matrix-js-sdk (GHSA-23cm-x6j7-6hq3)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-40823","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the homeserver to decrypt end-to-end encrypted messages sent by affected clients."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://github.com/matrix-org/matrix-js-sdk/releases/tag/v12.4.1","url":"https://github.com/matrix-org/matrix-js-sdk/releases/tag/v12.4.1"},{"refsource":"MISC","name":"https://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing","url":"https://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing"}]}},"nvd":{"publishedDate":"2021-09-13 19:15:00","lastModifiedDate":"2023-08-08 14:22:00","problem_types":["CWE-290"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:matrix:javascript_sdk:*:*:*:*:*:*:*:*","versionEndExcluding":"12.4.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"40823","Ordinal":"216581","Title":"CVE-2021-40823","CVE":"CVE-2021-40823","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"40823","Ordinal":"1","NoteData":"A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the homeserver to decrypt end-to-end encrypted messages sent by affected clients.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"40823","Ordinal":"2","NoteData":"2021-09-13","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"40823","Ordinal":"3","NoteData":"2021-09-14","Type":"Other","Title":"Modified"}]}}}