Search CVE reports


Toggle filters

31 – 40 of 40 results


CVE-2020-26257

Medium priority
Needs evaluation

Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-26890

Medium priority
Needs evaluation

Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Not affected Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-26891

Medium priority
Needs evaluation

AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2019-18835

Medium priority
Fixed

Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Not affected Fixed Not in release
Show less packages

CVE-2019-11842

Medium priority

Some fixes available 1 of 3

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Not affected Fixed Not in release
Show less packages

CVE-2019-5885

Medium priority

Some fixes available 1 of 2

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Not affected Fixed Not in release
Show less packages

CVE-2018-16515

Medium priority

Some fixes available 1 of 2

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Not affected Fixed Not in release
Show less packages

CVE-2018-12423

Low priority

Some fixes available 1 of 2

In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Not affected Not affected Fixed Not in release
Show less packages

CVE-2018-12291

Medium priority

Some fixes available 1 of 11

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Needs evaluation Not affected Not affected Fixed Not in release
Show less packages

CVE-2018-10657

Medium priority

Some fixes available 11 of 12

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
matrix-synapse Fixed Fixed Fixed Not in release
Show less packages