← voltar
CVE-2022-39264highCWE-287CWE-295

nheko vulnerable to secret poisoning using MITM on secret requests by the homeserver

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 8.6epss 0.7%
probabilidade de exploração
0.7%top 49% das CVEs
exploração observada
nãonenhuma fonte reporta
nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a workaround, one may apply the patch manually, avoid doing verifications of one's own devices, and/or avoid pressing the request button in the settings menu.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Produtos afetados
Nheko-Reborn · nheko