CVE-2018-12423: High severity matrix synapse vulnerability
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.powerlevels event in force.
Other sources
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.powerlevels event in force.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12423?
CVE-2018-12423 is a vulnerability in Synapse before version 0.31.2 that allows unauthorized users to hijack rooms when there is no 'm.room.power_levels' event in force.
What is the severity of CVE-2018-12423?
The severity of CVE-2018-12423 is high, with a severity value of 7.5.
How can unauthorized users hijack rooms in Synapse before 0.31.2?
Unauthorized users can hijack rooms in Synapse before 0.31.2 when there is no 'm.room.power_levels' event in force.
How can I fix CVE-2018-12423?
To fix CVE-2018-12423, update to Synapse version 0.31.2 or higher.
Where can I find more information about CVE-2018-12423?
You can find more information about CVE-2018-12423 on the NIST National Vulnerability Database (NVD) website.