CVE-2022-39254High· 8.6▾ TwilightWhen matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.6%
When matrix-nio before 0.20 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from.
This allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack.
If you have any questions or comments about this advisory, e-mail us at [email protected].
matrix-nio < 0.20Upgrade to a patched release:
matrix-nio 0.20