Lucene search

K
cveGitHub_MCVE-2024-34353
HistoryMay 14, 2024 - 3:38 p.m.

CVE-2024-34353

2024-05-1415:38:43
CWE-532
GitHub_M
web.nvd.nist.gov
37
matrix sdk
rust
encryption
key backup
logic bug
cryptography
asymmetric
tracing crate
vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0

Percentile

15.5%

The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side key backup stores encrypted copies of Matrix message keys. This facilitates key sharing between a user’s devices and provides a redundant copy in case all devices are lost. The key backup uses asymmetric
cryptography, with each server-side key backup assigned a unique public-private key pair. Due to a logic bug introduced in commit 71136e44c03c79f80d6d1a2446673bc4d53a2067, matrix-sdk-crypto version 0.7.0 will sometimes log the private part of the backup key pair to Rust debug logs (using the tracing crate). This issue has been resolved in matrix-sdk-crypto version 0.7.1. No known workarounds are available.

Affected configurations

Vulners
Node
matrix-orgmatrix_sdk_crypto
VendorProductVersionCPE
matrix-orgmatrix_sdk_crypto*cpe:2.3:a:matrix-org:matrix_sdk_crypto:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "matrix-org",
    "product": "matrix-sdk-crypto",
    "versions": [
      {
        "version": "= 0.7.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0

Percentile

15.5%

Related for CVE-2024-34353