HIGH
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs
Published Nov 7, 2019
8.8
HIGHCVSS 4.0
EPSS 0.86%
Description
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
Affected products
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0083 Advisory
- https://github.com/advisories/GHSA-cppw-2mf8-qpm5 Advisory
- https://github.com/matrix-org/synapse/commit/172f264ed38e8bef857552f93114b4ee113a880b
- https://github.com/matrix-org/synapse/pull/6262 x_refsource_MISCPatchThird Party Advisory
- https://github.com/matrix-org/synapse/releases/tag/v1.5.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2019-186.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2019-18835
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0083 | Advisory | |
| https://github.com/advisories/GHSA-cppw-2mf8-qpm5 | Advisory | |
| https://github.com/matrix-org/synapse/commit/172f264ed38e8bef857552f93114b4ee113a880b | ||
| https://github.com/matrix-org/synapse/pull/6262 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/matrix-org/synapse/releases/tag/v1.5.0 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2019-186.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-18835 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 7, 2019
Updated Aug 5, 2024
Reserved Nov 7, 2019
Link CVE-2019-18835
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-CPPW-2MF8-QPM5