Vulnerabilities/

matrix-js-sdk subject to impersonated messages due to permissive key forwarding

Severity:
High

Description

An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.

This attack is possible due to the matrix-js-sdk implementing a too permissive key forwarding strategy on the receiving end.

Recommendation

Update the matrix-js-sdk package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-js-sdk
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing