Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31889
HistorySep 01, 2021 - 3:33 a.m.

Privilege Escalation

2021-09-0103:33:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
privilege escalation
room id
private room
group/community features
information disclosure

EPSS

0.001

Percentile

49.7%

matrix-synapse is vulnerable to privilege escalation. Any unauthorized user who knows Room ID of a private room can disclose a private room’s name, avatar, topic, and number of members through Group/Community features.