Record summary

CVE-2018-10657 has a selected CVSS score of 7.5 (high).

Description

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 1, 2018 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 0.28.1 · Fixed in 0.28.1affected

References

5