CVE-2019-18835
08.11.2019, 00:15
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.Enginsight
Vendor | Product | Version |
---|---|---|
matrix | synapse | 𝑥 < 1.5.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration