Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39200

Опубликовано: 12 сент. 2022
Источник: nvd
CVSS3: 7.3
CVSS3: 5.3
EPSS Низкий

Описание

Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the /get_missing_events path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note that this does not apply to events retrieved through other endpoints (e.g. /event, /state) as they have been correctly verified. Homeservers that have federation disabled are not vulnerable. The problem has been fixed in Dendrite 0.9.8. Users are advised to upgrade. There are no known workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:matrix:dendrite:*:*:*:*:*:*:*:*
Версия до 0.9.8 (исключая)

EPSS

Процентиль: 37%
0.00158
Низкий

7.3 High

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.3
github
больше 3 лет назад

Dendrite signature checks not applied to some retrieved missing events

EPSS

Процентиль: 37%
0.00158
Низкий

7.3 High

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-347