QID 995440

Date Published: 2023-10-03

QID 995440: Python (Pip) Security Update for matrix-synapse (GHSA-7565-cq32-vx2x)

Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show the event as read by the user, even if they are not in the room.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-7565-cq32-vx2x for updates and patch information.
    Vendor References

    CVEs related to QID 995440

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7565-cq32-vx2x matrix-synapse URL Logo github.com/advisories/GHSA-7565-cq32-vx2x