Lucene search

K
osvGoogleOSV:CVE-2019-18835
HistoryNov 08, 2019 - 12:15 a.m.

CVE-2019-18835

2019-11-0800:15:10
Google
osv.dev
4

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

61.8%

Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

61.8%