Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-91275
HistoryNov 25, 2021 - 12:00 a.m.

Synapse path traversal vulnerability

2021-11-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
synapse
path traversal
authentication bypass
file download
remote server

EPSS

0.001

Percentile

50.2%

Synapse is an application. for open federated instant messaging and VoIPSynapse. versions prior to Synapse 1.47.1 contain a path traversal vulnerability that could be exploited by an attacker to bypass the authentication process and download files from a remote server to an arbitrary directory.