Vulnerabilities/

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

Severity:
Medium

Description

A logic error in the room key sharing functionality of matrix-js-sdk before 12.4.1 allows a malicious Matrix homeserver† participating in an encrypted room to steal room encryption keys from affected Matrix clients participating in that room. This allows the homeserver to decrypt end-to-end encrypted messages sent by affected clients.

Recommendation

Update the matrix-js-sdk package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-js-sdk
Anything's wrong? Let us know Last updated on August 08, 2023

This issue is available in SmartScanner Professional

See Pricing