VDB
KO
HIGH 7.5

GHSA-v8wm-g9f2-xjv4

Matrix Synapse Security Filtering Flaw

Details

The `on_get_missing_events` function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / matrix-synapse
Introduced in: 0 Fixed in: 0.31.1
Fix pip install --upgrade 'matrix-synapse>=0.31.1'

References