CVE-2024-52813
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 7, 2025
CWE ID 223
Summary
CVE-2024-52813 is a vulnerability affecting the matrix-rust-sdk, an implementation of a Matrix client-server library in Rust. Prior to version 0.8.0, the matrix-sdk-crypto Rust crate lacked a mechanism to notify client applications when a user's cryptographic identity transitions from verified to unverified. This oversight could cause relying applications to disregard such identity changes. The recently released version 0.8.0 introduces a new VerificationLevel::VerificationViolation enum variant to signal this occurrence.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- El Paso Multi-Agency Tactical Response Information eXchange