VDB
KO
HIGH 7.5

GHSA-ch5v-fhg8-7gv9

Matrix Synapse Authorization Error

Details

In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no `m.room.power_levels` event in force.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / matrix-synapse
Introduced in: 0 Fixed in: 0.31.2
Fix pip install --upgrade 'matrix-synapse>=0.31.2'

References