CVE-2024-52813
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/01/2025
Last modified:
07/01/2025
Description
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. matrix-sdk-crypto 0.8.0 adds a new VerificationLevel::VerificationViolation enum variant which indicates that a previously verified identity has been changed.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM