CVE-2018-16515
published 2018-09-18CVE-2018-16515: Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event…
PriorityP344high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.52%
71.8th percentile
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | matrix-synapse | < matrix-synapse 0.33.3.1-1 (forky) | matrix-synapse 0.33.3.1-1 (forky) |
| matrix | synapse | < 0.33.3.1 | 0.33.3.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Synapse vulnerabilities
vendor_ubuntu·2023-05-16·CVSS 7.5
CVE-2019-5885 [HIGH] Synapse vulnerabilities
Title: Synapse vulnerabilities
Summary: Several security issues were fixed in Synapse.
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2019-18835, CVE-2018-12291, CVE-2018-10657)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to hijack the
session. (CVE-2019-11842, CVE-2018-12423)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a re
Debian
CVE-2018-16515: matrix-synapse - Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possi...
vendor_debian·2018·CVSS 8.8
CVE-2018-16515 [HIGH] CVE-2018-16515: matrix-synapse - Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possi...
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
Scope: local
forky: resolved (fixed in 0.33.3.1-1)
sid: resolved (fixed in 0.33.3.1-1)
OSV
matrix-synapse vulnerabilities
osv·2023-05-16·CVSS 7.5
CVE-2019-18835 [HIGH] matrix-synapse vulnerabilities
matrix-synapse vulnerabilities
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2019-18835, CVE-2018-12291, CVE-2018-10657)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to hijack the
session. (CVE-2019-11842, CVE-2018-12423)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to perform
sp
GHSA
Matrix Synapse Improper Signature Validation
ghsa·2022-05-13
CVE-2018-16515 [HIGH] CWE-347 Matrix Synapse Improper Signature Validation
Matrix Synapse Improper Signature Validation
Matrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
OSV
Matrix Synapse Improper Signature Validation
osv·2022-05-13
CVE-2018-16515 [HIGH] Matrix Synapse Improper Signature Validation
Matrix Synapse Improper Signature Validation
Matrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
OSV
CVE-2018-16515: Matrix Synapse before 0
osv·2018-09-18·CVSS 8.8
CVE-2018-16515 [HIGH] CVE-2018-16515: Matrix Synapse before 0
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
No detection rules found.
No public exploits indexed.
https://github.com/matrix-org/synapse/issues/3796#event-1833126269https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRW7YR2H3ASUSYX4AO4KMY3FNVDNYW3P/https://matrix.org/blog/2018/09/06/critical-security-update-synapse-0-33-3-1/https://github.com/matrix-org/synapse/issues/3796#event-1833126269https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRW7YR2H3ASUSYX4AO4KMY3FNVDNYW3P/https://matrix.org/blog/2018/09/06/critical-security-update-synapse-0-33-3-1/
2018-09-18
Published