In Synapse prima di 0.31.2, gli utenti non autorizzati possono dirottare camere quando non v’è alcun evento m.room.power_levels in vigore. |
https://bugs.debian.org/901549 https://github.com/matrix-org/matrix-doc/issues/1304 https://matrix.org/blog/2018/06/14/security-update-synapse-0-31-2/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12423 |
Vulnerabilità: CVE-2018-12423
