Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| matrix-synapse(PyPI) | 0.33.3 | 0.33.3.1 | N/A |
| matrix-synapse(PyPI) | 0 | 0.33.2.1 | N/A |
CVSS Metrics