matrix-nio_project CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

matrix-nio_project vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to matrix-nio_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-39254 matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue. [email protected] 8.6 0.23% 2022-09-29 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence