Vulnerability GHSA-r5vf-wf4h-82gg
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
January 07, 2025 at 03:25 PM UTC
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
0.1.0 - 0.7.2
0.1.0 - 0.7.2
Summary
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
Details
Impact
Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes.
Patches
matrix-sdk-crypto 0.8.0 adds a new VerificationLevel::VerificationViolation enum variant which indicates that a previously verified identity has been changed.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 days ago
Sending custom to-device messages may panics
0.1.0 - 0.18.0 RUSTSEC-2026-0318
0.1.0 - 0.18.0 RUSTSEC-2026-0318
Medium Risk
3 months ago
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
Unknown
4 months ago
Sender-binding gaps in to-device messages
0.12.0 - 0.16.0 RUSTSEC-2026-0159
0.12.0 - 0.16.0 RUSTSEC-2026-0159
Medium Risk
1 year ago
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
0.8.0 - 0.11.0 RUSTSEC-2025-0041
0.8.0 - 0.11.0 RUSTSEC-2025-0041
Medium Risk
1 year ago
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
Impacted packages
Timeline
Published
1 year ago
January 07, 2025 at 03:25 PM UTC
Fixed (0.8.0)
1 year ago
November 19, 2024 at 01:14 PM UTC
Last Modified
1 year ago
January 22, 2025 at 05:37 PM UTC