GHSA-cppw-2mf8-qpm5
Dashboard / Vulnerabilities / GHSA-cppw-2mf8-qpm5
GHSA-cppw-2mf8-qpm5
Summary: Improper Verification of Cryptographic Signature in matrix-synapse
Details: Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over `/send_join`, `/send_leave`, and `/invite` may not be correctly signed, or may not come from the expected servers.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-18835, https://github.com/matrix-org/synapse/pull/6262, https://github.com/matrix-org/synapse/commit/172f264ed38e8bef857552f93114b4ee113a880b, https://github.com/matrix-org/synapse, https://github.com/matrix-org/synapse/releases/tag/v1.5.0, https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2019-186.yaml
Affected packages
Package
Name: matrix-synapse
Purl: pkg:pypi/matrix-synapse
Affected ranges
Type: ECOSYSTEM
Events:
