matrix-synapse is vulnerable to Improper Verification of Data Authenticity
71
High Risk
When handling remote room joins, Synapse does not sufficiently verify tombstone and room-upgrade predecessor relationships. A malicious federated homeserver, in cooperation with or by tricking a local user, can cause a room alias to be redirected so its destination room changes. This lets an existing alias point users to an unintended, attacker-influenced room. The fix verifies tombstone and upgrade predecessors before accepting the relationship.
You are affected if you are using a version that falls within the vulnerable range, your homeserver participates in open federation, and a local authenticated user can be induced to join or cooperate with an untrusted federated room that abuses tombstone or room-upgrade predecessor relationships to redirect a room alias.
matrix-synapse is vulnerable to Improper Verification of Data Authenticity in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant