VDB
KO

PYSEC-2019-186

Details

Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / matrix-synapse
Introduced in: 0 Fixed in: 1.5.0
Fix pip install --upgrade 'matrix-synapse>=1.5.0'

References