Key Exchange without Entity Authentication Affecting org.matrix.android:matrix-android-sdk2 package, versions [,1.5.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGMATRIXANDROID-3035798
  • published29 Sept 2022
  • disclosed29 Sept 2022
  • creditUnknown

Introduced: 29 Sep 2022

CVE-2022-39246  (opens in a new tab)
CWE-322  (opens in a new tab)

How to fix?

Upgrade org.matrix.android:matrix-android-sdk2 to version 1.5.1 or higher.

Overview

org.matrix.android:matrix-android-sdk2 is a Matrix SDK for Android, extracted from the Element Android application.

Affected versions of this package are vulnerable to Key Exchange without Entity Authentication due to the key forwarding strategy implemented in the matrix-android-sdk2 that is too permissive. An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.

CVSS Scores

version 3.1