CVE-2018-16515

HIGH

Matrix Synapse < 0.33.3.1 - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0152
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (3)
debian/debian_linux 8.0
matrix/synapse < 0.33.3.1
pypi/matrix-synapse 0.33.3 - 0.33.3.1PyPI
Published Sep 18, 2018
Tracked Since Feb 18, 2026