matrix-synapse is vulnerable to Spoofing
75
High Risk
Synapse accepts to-device messages from remote homeservers without verifying that the message sender belongs to the originating server. A malicious federated homeserver can spoof the sender field so that a to-device message appears to have come from a different homeserver. This allows impersonation of users on other servers in to-device traffic. The fix validates the message origin against the claimed sender.
You are affected if you are using a version that falls within the vulnerable range and your homeserver participates in open federation.
matrix-synapse is vulnerable to Spoofing in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant