Matrix · Matrix Synapse · CVE-2018-12291
**Name of the Vulnerable Software and Affected Versions**
Matrix Synapse versions prior to 0.31.1
**Description**
The issue concerns a security bug in the get missing events federation API, specifically in the `on get missing events` function, where event visibility rules were not applied correctly.
**Recommendations**
For versions prior to 0.31.1, update to version 0.31.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the `on get missing events` function in handlers/federation.py until a patch is available.