CVE-2018-16515

HIGH8.8EPSS 0.44%

Matrix Synapse Improper Signature Validation

Published: 5/13/2022Modified: 5/20/2026
Also known as:DEBIAN-CVE-2018-16515

Description

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (10)