Lucene search

K
freebsdFreeBSD93EB0E48-14BA-11EC-875E-901B0E9408DC
HistoryAug 23, 2021 - 12:00 a.m.

Matrix clients -- several vulnerabilities

2021-08-2300:00:00
vuxml.freebsd.org
22
matrix clients
element
fluffychat
nheko
cinny
schildichat
encryption keys
vulnerabilities
compromised accounts
attacker

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

36.0%

Matrix developers report:

Today we are disclosing a critical security issue affecting
multiple Matrix clients and libraries including Element
(Web/Desktop/Android), FluffyChat, Nheko, Cinny, and SchildiChat.
Specifically, in certain circumstances it may be possible to
trick vulnerable clients into disclosing encryption keys for
messages previously sent by that client to user accounts later
compromised by an attacker.
Exploiting this vulnerability to read encrypted messages requires
gaining control over the recipient’s account. This requires either
compromising their credentials directly or compromising their homeserver.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchcinny<Β 1.2.1UNKNOWN
FreeBSDanynoarchelement-web<Β 1.8.3UNKNOWN
FreeBSDanynoarchnheko<=Β 0.8.2_2UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

36.0%