CVE-2022-39249
published 2022-09-28CVE-2022-39249: Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.99%
58.6th percentile
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible due to the matrix-js-sdk implementing a too permissive key forwarding strategy on the receiving end. Starting with version 19.7.0, the default policy for accepting key forwards has been made more strict in the matrix-js-sdk. matrix-js-sdk will now only accept forwarded keys in response to previously issued requests and only from own, verified devices. The SDK now sets a `trusted` flag on the decrypted message upon decryption, based on whether the key used to decrypt the message was received from a trusted source. Clients need to ensure that messages decrypted with a key with `trusted = false` are decorated appropriately, for example, by showing a warning for such messages. This attack requires coordination between a malicious homeserver and an attacker, and those who trust your homeservers do not need a workaround.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-matrix-js-sdk | — | — |
| matrix-org | matrix-js-sdk | < 19.7.0 | 19.7.0 |
| matrix-org | matrix-js-sdk | >= 0 < 19.7.0 | 19.7.0 |
| matrix | javascript_sdk | < 19.7.0 | 19.7.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:102.4.2+build2-0ubuntu0.18.04.1 | 1:102.4.2+build2-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.4.2+build2-0ubuntu0.20.04.1 | 1:102.4.2+build2-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.4.2+build2-0ubuntu0.22.04.1 | 1:102.4.2+build2-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
thunderbird vulnerabilities
osv·2022-11-11·CVSS 5.5
CVE-2022-3266 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
bypass Content Security Policy (CSP) or other security restrictions, or
execute arbitrary code. These issues only affect Ubuntu 18.04 LTS, Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-3266, CVE-2022-40956,
CVE-2022-40957, CVE-2022-40958, CVE-2022-40959, CVE-2022-40960,
CVE-2022-40962)
Multiple security issues were discovered in the Matrix SDK bundled with
Thunderbird. An attacker could potentially exploit these in order to
impersonate another user. These issues only affect Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-392
GHSA
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
ghsa·2022-09-30
CVE-2022-39249 [HIGH] CWE-287 matrix-js-sdk subject to impersonated messages due to permissive key forwarding
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
## Impact
An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.
This attack is possible due to the matrix-js-sdk implementing a too permissive [key forwarding](https://spec.matrix.org/v1.3/client-server-api/#key-requests) strategy on the receiving end.
Key forwarding is a mechanism allowing clients to recover from “unable to decrypt” messages when they missed the initial key distribution, at the time the message was originally sent. Examples include accessing message history before they joined the room but also when some network/federation err
OSV
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
osv·2022-09-30
CVE-2022-39249 [HIGH] matrix-js-sdk subject to impersonated messages due to permissive key forwarding
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
## Impact
An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.
This attack is possible due to the matrix-js-sdk implementing a too permissive [key forwarding](https://spec.matrix.org/v1.3/client-server-api/#key-requests) strategy on the receiving end.
Key forwarding is a mechanism allowing clients to recover from “unable to decrypt” messages when they missed the initial key distribution, at the time the message was originally sent. Examples include accessing message history before they joined the room but also when some network/federation err
OSV
CVE-2022-39249: Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript
osv·2022-09-28·CVSS 7.5
CVE-2022-39249 [HIGH] CVE-2022-39249: Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible due to the matrix-js-sdk implementing a too permissive key forwarding strategy on the receiving end. Starting with version 19.7.0, the default policy for accepting key forwards has been made more strict in the matrix-js-sdk. matrix-js-sdk will now only accept forwarded keys in response to previously issued requests and only from own, verified devices. The SDK now sets a `trusted` flag on the decrypted message upon decryption, based on whether the key used
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2022-11-11·CVSS 5.5
CVE-2022-40956 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
bypass Content Security Policy (CSP) or other security restrictions, or
execute arbitrary code. These issues only affect Ubuntu 18.04 LTS, Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-3266, CVE-2022-40956,
CVE-2022-40957, CVE-2022-40958, CVE-2022-40959, CVE-2022-40960,
CVE-2022-40962)
Multiple security issues were discovered in the Matrix SDK bundled with
Thunderbird. An attacker could potentially exploit these in order to
impersonate another user. These issues only affect Ub
Red Hat
Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators
vendor_redhat·2022-09-28·CVSS 7.5
CVE-2022-39249 [HIGH] CWE-287 Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators
Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible due to the matrix-js-sdk implementing a too permissive key forwarding strategy on the receiving end. Starting with version 19.7.0, the default policy for accepting key forwards has been made more strict in the matrix-js-sdk. matrix-js-sdk will now only accept forwarded keys in response to previously issued requests and only from own, verif
Debian
CVE-2022-39249: node-matrix-js-sdk - Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to v...
vendor_debian·2022·CVSS 7.5
CVE-2022-39249 [HIGH] CVE-2022-39249: node-matrix-js-sdk - Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to v...
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible due to the matrix-js-sdk implementing a too permissive key forwarding strategy on the receiving end. Starting with version 19.7.0, the default policy for accepting key forwards has been made more strict in the matrix-js-sdk. matrix-js-sdk will now only accept forwarded keys in response to previously issued requests and only from own, verified devices. The SDK now sets a `trusted` flag on the decrypted message upon decryption, based on whether the key used
Mozilla
Mozilla Foundation Security Advisory 2022-43: CVE-2022-39249
vendor_mozilla·CVSS 7.5
CVE-2022-39249 [HIGH] Mozilla Foundation Security Advisory 2022-43: CVE-2022-39249
Mozilla Foundation Security Advisory 2022-43
CVE: CVE-2022-39249
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 102.3.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/matrix-js-sdk/commit/a587d7c36026fe1fcf93dfff63588abee359be76https://github.com/matrix-org/matrix-js-sdk/releases/tag/v19.7.0https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-6263-x97c-c4gghttps://github.com/matrix-org/matrix-spec-proposals/pull/3061https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clientshttps://security.gentoo.org/glsa/202210-35https://github.com/matrix-org/matrix-js-sdk/commit/a587d7c36026fe1fcf93dfff63588abee359be76https://github.com/matrix-org/matrix-js-sdk/releases/tag/v19.7.0https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-6263-x97c-c4gghttps://github.com/matrix-org/matrix-spec-proposals/pull/3061https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clientshttps://security.gentoo.org/glsa/202210-35
2022-09-28
Published