matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. matrix-sdk-crypto 0.8.0 adds a new VerificationLevel::VerificationViolation enum variant which indicates that a previously verified identity has been changed.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Jan 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. matrix-sdk-crypto 0.8.0 adds a new VerificationLevel::VerificationViolation enum variant which indicates that a previously verified identity has been changed. | |
Title | matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity | |
Weaknesses | CWE-223 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-07T15:25:47.794Z
Updated: 2025-01-07T17:11:35.476Z
Reserved: 2024-11-15T17:11:13.444Z
Link: CVE-2024-52813
Vulnrichment
Updated: 2025-01-07T17:11:31.733Z
NVD
Status : Received
Published: 2025-01-07T16:15:35.610
Modified: 2025-01-07T16:15:35.610
Link: CVE-2024-52813
Redhat
No data.