Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37351
HistorySep 30, 2022 - 6:50 a.m.

Authorization Bypass

2022-09-3006:50:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
matrix_nio vulnerability
authorization bypass
homeserver
impersonation attack
software

0.001 Low

EPSS

Percentile

19.4%

matrix_nio is vulnerable to authorization bypass. The library correctly accepts key forwards only if they are a response to a previous request and doesn’t check whether the device that responded matches the device the key was requested from, which allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack.

CPENameOperatorVersion
matrix-niole0.19.0
matrix-niole0.19.0

0.001 Low

EPSS

Percentile

19.4%