GHSA-j8cm-g7r6-hfpq
LOWCVE-2024-40640Versions before 0.7.0 of vodozemac use a non-constant time base64 implementation for importing key material for Megolm group sessions and PkDecryption Ed25519 secret keys. This flaw might allow an attacker to infer some information about the secret key material through a side-channel attack.
- Affected
- >=0.0.0-0, <0.7.0
- Fixed in
- 0.7.0
- Weakness
- CWE-208
- Published
- 2024-07-17
- Source
- github