Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Neilisfragile

#36054de 53,633
7.5CVSS total
Vulnerabilidades · 1
PT-2018-11098
7.5
2018-06-13
Matrix · Matrix Synapse · CVE-2018-12291
**Name of the Vulnerable Software and Affected Versions** Matrix Synapse versions prior to 0.31.1 **Description** The issue concerns a security bug in the get missing events federation API, specifically in the `on get missing events` function, where event visibility rules were not applied correctly. **Recommendations** For versions prior to 0.31.1, update to version 0.31.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the `on get missing events` function in handlers/federation.py until a patch is available.