Safety vulnerability ID: 54217
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
Affected functions:
synapse.handlers.federation.FederationHandler.on_make_join_request
synapse.handlers.federation.FederationHandler.on_make_leave_request
synapse.federation.federation_server.FederationServer.on_invite_request
synapse.federation.federation_server.FederationServer.on_send_join_request
synapse.federation.federation_server.FederationServer.on_send_leave_request
Latest version: 1.121.1
Homeserver for the Matrix decentralised comms protocol
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application