PT-2018-13604 · Matrix+2 · Matrix Synapse+2

Richvdh

·

Published

2018-09-18

·

Updated

2023-05-16

·

CVE-2018-16515

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Matrix Synapse versions prior to 0.33.3.1 Matrix Synapse version 0.33.2.1
Description The issue allows remote attackers to spoof events and possibly have other impacts by leveraging improper transaction and event signature validation.
Recommendations For Matrix Synapse versions prior to 0.33.3.1, update to version 0.33.3.1 or later. For Matrix Synapse version 0.33.2.1, update to version 0.33.3.1 or later.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2390
CVE-2018-16515
GHSA-FMVH-RVQ5-HHJX
USN-6076-1

Affected Products

Alt Linux
Matrix Synapse
Ubuntu