CVE-2024-52813
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. matrix-sdk-crypto 0.8.0 adds a new VerificationLevel::VerificationViolation enum variant which indicates that a previously verified identity has been changed.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.48%
- CWE
- CWE-223
- Published
- 2025-01-07
- Last modified
- 2026-03-13
Affected products
- matrix-org matrix-rust-sdk
Weakness type
Related vulnerabilities
- CVE-2026-49426 — Incorrect audit records for ptrace(2) syscall requests
- CVE-2025-35987 — Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center...
- CVE-2026-31890 — Inspektor Gadget: Tracing Denial of Service via Event Flooding
- CVE-2025-52926 — In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the...
- CVE-2023-31191 — Denial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark Innovations
- CVE-2023-29156 — Denial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark Innovations
- CVE-2023-28360 — An omission of security-relevant information vulnerability exists in Brave desktop prior to version...
- CVE-2022-44646 — In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's...