cbcvebase.
CVE-2022-39251
published 2022-09-28

CVE-2022-39251: Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.91%
56.0th percentile
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This attack requires coordination between a malicious home server and an attacker, so those who trust their home servers do not need a workaround.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiannode-matrix-js-sdk
matrix-orgmatrix-js-sdk< 19.7.019.7.0
matrix-orgmatrix-js-sdk>= 0 < 19.7.019.7.0
matrixjavascript_sdk< 19.7.019.7.0
mozillafirefox
mozillathunderbird>= 0 < 1:102.4.2+build2-0ubuntu0.18.04.11:102.4.2+build2-0ubuntu0.18.04.1
mozillathunderbird>= 0 < 1:102.4.2+build2-0ubuntu0.20.04.11:102.4.2+build2-0ubuntu0.20.04.1
mozillathunderbird>= 0 < 1:102.4.2+build2-0ubuntu0.22.04.11:102.4.2+build2-0ubuntu0.22.04.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.