Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
References
Configurations
History
21 Nov 2024, 03:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/matrix-org/synapse/issues/3796#event-1833126269 - Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRW7YR2H3ASUSYX4AO4KMY3FNVDNYW3P/ - | |
References | () https://matrix.org/blog/2018/09/06/critical-security-update-synapse-0-33-3-1/ - Vendor Advisory |
07 Nov 2023, 02:53
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2018-09-18 21:29
Updated : 2024-11-21 03:52
NVD link : CVE-2018-16515
Mitre link : CVE-2018-16515
CVE.ORG link : CVE-2018-16515
JSON object : View
Products Affected
debian
- debian_linux
matrix
- synapse
CWE
CWE-347
Improper Verification of Cryptographic Signature