Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31895
HistorySep 01, 2021 - 7:35 a.m.

Privilege Escalation

2021-09-0107:35:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
vulnerability
privilege escalation
unauthorized access
room id
history visibility

EPSS

0.001

Percentile

35.6%

matrix_synapse is vulnerable to privilege escalation. An unauthorised user knowing Room ID of a private room and setting room’s history visibility to shared is allowed to enumerate the room’s members, including their display names.