PT-2022-24854 · Nheko+1 · Nheko+1
Deepbluev7
+1
·
Published
2022-09-28
·
Updated
2024-02-08
·
CVE-2022-39264
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
nheko versions prior to 0.10.2
Description
nheko is a desktop client for the Matrix communication application. The issue allows homeservers to insert malicious secrets, which could lead to man-in-the-middle attacks.
Recommendations
For versions prior to 0.10.2, upgrade to version 0.10.2 to protect against this issue.
As a temporary workaround, consider applying the patch manually.
Avoid doing verifications of one's own devices until the issue is resolved.
Restrict access to the request button in the settings menu to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Nheko