GHSA-pfw4-xjgm-267c
Dashboard / Vulnerabilities / GHSA-pfw4-xjgm-267c
Summary: Dendrite signature checks not applied to some retrieved missing events
Details: ### Impact Events retrieved from a remote homeserver using `/get_missing_events` did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note that this does not apply to events retrieved through other endpoints (e.g. `/event`, `/state`) as they have been correctly verified. Homeservers that have federation disabled are not vulnerable. ### Patches The problem has been fixed in Dendrite 0.9.8. ### Workarounds There are no workarounds. ### Special thanks Tulir Asokan, who spotted the issue originally.
References: https://github.com/matrix-org/dendrite/security/advisories/GHSA-pfw4-xjgm-267c, https://nvd.nist.gov/vuln/detail/CVE-2022-39200, https://github.com/matrix-org/dendrite/commit/2792d0490f3771488bad346981b8c26479a872c3, https://github.com/matrix-org/dendrite
Affected packages
Package
Name: github.com/matrix-org/dendrite
Purl: pkg:golang/github.com/matrix-org/dendrite
Affected ranges
Type: SEMVER
Events:
