Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-40823
HistorySep 13, 2021 - 12:00 a.m.

CVE-2021-40823

2021-09-1300:00:00
ubuntu.com
ubuntu.com
16
logic error
room key sharing
matrix javascript sdk
cve-2021-40823
encryption keys
malicious homeserver
encrypted messages

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

36.0%

A logic error in the room key sharing functionality of matrix-js-sdk (aka
Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver
present in an encrypted room to steal room encryption keys (via crafted
Matrix protocol messages) that were originally sent by affected Matrix
clients participating in that room. This allows the homeserver to decrypt
end-to-end encrypted messages sent by affected clients.

Bugs

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

36.0%