Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29519
HistoryFeb 28, 2021 - 1:22 a.m.

Insecure Access Controls

2021-02-2801:22:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
authorization bypass
user domains
restrictions
internal infrastructure
software
vulnerability

EPSS

0.001

Percentile

39.4%

matrix-synapse is vulnerable to authorization bypass. Requests to user provided domains were not restricted to external IP addresses when calculating the key validity for third-party invite events and sending push notifications, potentially resulting in Synapse to make requests to the internal infrastructure.

EPSS

0.001

Percentile

39.4%