GHSA-7565-cq32-vx2x

    Dashboard / Vulnerabilities / GHSA-7565-cq32-vx2x

    GHSA-7565-cq32-vx2x

    Published: 26 Sept 2023Last Modified: 10 Sept 2026

    Summary: matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

    Details: ### Impact Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show the event as read by the user, even if they are not in the room. ### Patches https://github.com/matrix-org/synapse/pull/16327 ### Workarounds There is no workaround.

    Affected packages

    Package

    Name: matrix-synapse

    Purl: pkg:pypi/matrix-synapse

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.34.0
    Fixed -1.93.0

    Affected versions

    0.34.0
    0.34.0.1
    0.34.1.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7565-cq32-vx2x | CVE-DB