CVE-2018-12291

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/06/2018
Last modified:
03/10/2019

Description

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* 0.31.1 (excluding)