—
RUSTSEC-2024-0434
Missing facility to signal rotation of a verified cryptographic identity
Details
Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes.
matrix-sdk-crypto 0.8.0 adds a new `VerificationLevel::VerificationViolation` enum variant which indicates that a previously verified identity has been changed.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/matrix-sdk-crypto
Introduced in:
0.0.0-0Fixed in: 0.8.0Upgrade matrix-sdk-crypto to 0.8.0 or newer (ecosystem crates.io).