CVE-2018-16515Improper Verification of Cryptographic Signature in Synapse

Severity
8.8HIGHNVD
EPSS
0.5%
top 32.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 16

Description

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDmatrix/synapse< 0.33.3.1

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

4
GHSA
Matrix Synapse Improper Signature Validation2022-05-13
OSV
Matrix Synapse Improper Signature Validation2022-05-13
CVEList
CVE-2018-16515: Matrix Synapse before 02018-09-18
OSV
CVE-2018-16515: Matrix Synapse before 02018-09-18

📋Vendor Advisories

2
Ubuntu
Synapse vulnerabilities2023-05-16
Debian
CVE-2018-16515: matrix-synapse - Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possi...2018

💬Community

1
Bugzilla
CVE-2018-16515 matrix-synapse: pre-disclosure of critical vulnerability2018-09-06
CVE-2018-16515 — Matrix Synapse vulnerability | cvebase