matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
Moderate severity
GitHub Reviewed
Published
Jan 7, 2025
in
matrix-org/matrix-rust-sdk
•
Updated Jan 7, 2025
Description
Published to the GitHub Advisory Database
Jan 7, 2025
Reviewed
Jan 7, 2025
Published by the National Vulnerability Database
Jan 7, 2025
Last updated
Jan 7, 2025
Impact
Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes.
Patches
matrix-sdk-crypto 0.8.0 adds a new
VerificationLevel::VerificationViolation
enum variant which indicates that a previously verified identity has been changed.Workarounds
N/A
References
References