VDB
Sign up
MEDIUM4.9

GHSA-h97m-27fx-42rx

matrix-sdk-ui: Incomplete edit validation

Details

### Impact The message edit validation logic in the `matrix-sdk-ui` crate before 0.16.1 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrator (or an actor with equivalent power) to impersonate or spoof messages as if they were sent by a victim user.

### Patches `matrix-sdk-ui` 0.16.1 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification.

### Workarounds N/A

### References * Pull request: https://github.com/matrix-org/matrix-rust-sdk/pull/6454

### For more information If you have any questions or comments about this advisory, please email us at [security at matrix.org](mailto:security@matrix.org).

[^1]: https://spec.matrix.org/unstable/client-server-api/#validity-of-replacement-events

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/matrix-sdk-ui
Introduced in: 0Fixed in: 0.16.1

Upgrade matrix-sdk-ui to 0.16.1 or newer (ecosystem crates.io).

References