cbcvebase.
CVE-2018-12291
published 2018-06-13

CVE-2018-12291: The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where…

high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianmatrix-synapse< matrix-synapse 0.31.1+dfsg-1 (forky)matrix-synapse 0.31.1+dfsg-1 (forky)
matrixsynapse< 0.31.10.31.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH