VDB
Sign up
—

RUSTSEC-2024-0434

Missing facility to signal rotation of a verified cryptographic identity

Details

Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes.

matrix-sdk-crypto 0.8.0 adds a new `VerificationLevel::VerificationViolation` enum variant which indicates that a previously verified identity has been changed.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/matrix-sdk-crypto
Introduced in: 0.0.0-0Fixed in: 0.8.0

Upgrade matrix-sdk-crypto to 0.8.0 or newer (ecosystem crates.io).

References