Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
References
Configurations
History
No history.
Information
Published : 2018-09-18 21:29
Updated : 2023-11-07 02:53
NVD link : CVE-2018-16515
Mitre link : CVE-2018-16515
CVE.ORG link : CVE-2018-16515
JSON object : View
Products Affected
matrix
- synapse
debian
- debian_linux
CWE
CWE-347
Improper Verification of Cryptographic Signature