First published: Thu Jun 14 2018(Updated: )
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no `m.room.power_levels` event in force.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matrix Synapse | <0.31.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12423 is a vulnerability in Synapse before version 0.31.2 that allows unauthorized users to hijack rooms when there is no 'm.room.power_levels' event in force.
The severity of CVE-2018-12423 is high, with a severity value of 7.5.
Unauthorized users can hijack rooms in Synapse before 0.31.2 when there is no 'm.room.power_levels' event in force.
To fix CVE-2018-12423, update to Synapse version 0.31.2 or higher.
You can find more information about CVE-2018-12423 on the NIST National Vulnerability Database (NVD) website.