Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Matrix Synapse Security Filtering Flaw

GHSA-v8wm-g9f2-xjv4 · CVE-2018-12291

Published · Modified

Description

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

Ready to move

Start Securing

Free, no credit card | First findings in minutes