CVE-2024-45192: Medium severity matrix olm vulnerability
An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45192?
CVE-2024-45192 is considered a moderate severity vulnerability due to its potential to expose sensitive session keys through cache-timing attacks.
How do I fix CVE-2024-45192?
To fix CVE-2024-45192, users should upgrade to a later version of Matrix libolm that addresses the vulnerability.
Which versions of Matrix libolm are affected by CVE-2024-45192?
CVE-2024-45192 affects Matrix libolm versions up to and including 3.2.16.
Does CVE-2024-45192 affect all Matrix libolm products?
CVE-2024-45192 specifically affects Matrix libolm products that are no longer supported by the maintainer.
What type of attack does CVE-2024-45192 expose to users?
CVE-2024-45192 exposes users to cache-timing attacks due to insecure handling of base64 decoding in group session keys.