Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12291

Опубликовано: 13 июн. 2018
Источник: debian

Описание

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
matrix-synapsefixed0.31.1+dfsg-1package

Примечания

  • https://github.com/matrix-org/synapse/pull/3371

  • https://github.com/matrix-org/synapse/commit/0834b49c6a9b6c597a154d4b2dfcf8fff90699ec

  • https://matrix.org/blog/2018/06/08/synapse-0-31-1-released/

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

CVSS3: 7.5
nvd
больше 7 лет назад

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

suse-cvrf
больше 7 лет назад

Security update for matrix-synapse

CVSS3: 7.5
github
больше 3 лет назад

Matrix Synapse Security Filtering Flaw