Vulnerabilities/

matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification

Severity:
High

Description

An attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’ identities, leading to the other device trusting/verifying the user identity under the control of the homeserver instead of the intended one.

Recommendation

Update the matrix-js-sdk package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-js-sdk
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing