Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-10657

Опубликовано: 02 мая 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*
Версия до 0.28.1 (исключая)

EPSS

Процентиль: 73%
0.01522
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

CVSS3: 7.5
debian
больше 8 лет назад

Matrix Synapse before 0.28.1 is prone to a denial of service flaw wher ...

CVSS3: 7.5
github
больше 4 лет назад

Matrix Synapse DoS

EPSS

Процентиль: 73%
0.01522
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20