Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-39251
HistorySep 28, 2022 - 12:00 a.m.

CVE-2022-39251

2022-09-2800:00:00
ubuntu.com
ubuntu.com
8
matrix javascript sdk
vulnerability
counterfeit messages
protocol confusion
megolm
olm
targeted attack
javascript

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

45.5%

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior
to version 19.7.0, an attacker cooperating with a malicious homeserver can
construct messages that legitimately appear to have come from another
person, without any indication such as a grey shield. Additionally, a
sophisticated attacker cooperating with a malicious homeserver could employ
this vulnerability to perform a targeted attack in order to send fake
to-device messages appearing to originate from another user. This can
allow, for example, to inject the key backup secret during a
self-verification, to make a targeted device start using a malicious key
backup spoofed by the homeserver. These attacks are possible due to a
protocol confusion vulnerability that accepts to-device messages encrypted
with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has
been modified to only accept Olm-encrypted to-device messages. Out of
caution, several other checks have been audited or added. This attack
requires coordination between a malicious home server and an attacker, so
those who trust their home servers do not need a workaround.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchnode-matrix-js-sdk< anyUNKNOWN
ubuntu22.04noarchnode-matrix-js-sdk< anyUNKNOWN
ubuntu23.10noarchnode-matrix-js-sdk< anyUNKNOWN
ubuntu24.04noarchnode-matrix-js-sdk< anyUNKNOWN
ubuntu18.04noarchthunderbird< 1:102.4.2+build2-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchthunderbird< 1:102.4.2+build2-0ubuntu0.20.04.1UNKNOWN
ubuntu22.04noarchthunderbird< 1:102.4.2+build2-0ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchthunderbird< 1:102.4.2+build2-0ubuntu0.22.10.1UNKNOWN

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

45.5%