Lucene search

K
osvGoogleOSV:GHSA-FMVH-RVQ5-HHJX
HistoryMay 13, 2022 - 1:50 a.m.

Matrix Synapse Improper Signature Validation

2022-05-1301:50:21
Google
osv.dev
9
matrix
synapse
improper
signature
validation
software
remote
attackers
spoof
events

AI Score

9

Confidence

High

EPSS

0.003

Percentile

70.2%

Matrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

AI Score

9

Confidence

High

EPSS

0.003

Percentile

70.2%