PT-2018-13604 · Matrix+2 · Matrix Synapse+2

Richvdh

·

Publicado

2018-09-18

·

Atualizado

2023-05-16

·

CVE-2018-16515

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Matrix Synapse versions prior to 0.33.3.1 Matrix Synapse version 0.33.2.1
Description The issue allows remote attackers to spoof events and possibly have other impacts by leveraging improper transaction and event signature validation.
Recommendations For Matrix Synapse versions prior to 0.33.3.1, update to version 0.33.3.1 or later. For Matrix Synapse version 0.33.2.1, update to version 0.33.3.1 or later.

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2390
CVE-2018-16515
GHSA-FMVH-RVQ5-HHJX
USN-6076-1

Produtos afetados

Alt Linux
Matrix Synapse
Ubuntu