VDB
KO
HIGH 8.8

GHSA-fmvh-rvq5-hhjx

Matrix Synapse Improper Signature Validation

Details

Matrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / matrix-synapse
Introduced in: 0.33.3 Fixed in: 0.33.3.1
Fix pip install --upgrade 'matrix-synapse>=0.33.3.1'
PyPI / matrix-synapse
Introduced in: 0 Fixed in: 0.33.2.1
Fix pip install --upgrade 'matrix-synapse>=0.33.2.1'

References