CVE-2018-16515: High severity matrix synapse vulnerability
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
Other sources
Matrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16515?
The severity of CVE-2018-16515 is high with a severity value of 8.8.
How can remote attackers exploit CVE-2018-16515?
Remote attackers can spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation in Matrix Synapse before version 0.33.3.1 and 0.33.2.1.
How can I fix CVE-2018-16515 in Matrix Synapse?
To fix CVE-2018-16515 in Matrix Synapse, update to version 0.33.3.1 or 0.33.2.1.
Are there any references for CVE-2018-16515?
Yes, you can find references for CVE-2018-16515 at the following links: [Link 1](https://nvd.nist.gov/vuln/detail/CVE-2018-16515), [Link 2](https://github.com/matrix-org/synapse/issues/3796#event-1833126269), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IRW7YR2H3ASUSYX4AO4KMY3FNVDNYW3P/).
What Common Weakness Enumeration (CWE) category does CVE-2018-16515 belong to?
CVE-2018-16515 belongs to CWE category 347.