FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

py-matrix-synapse -- missing signature checks on some federation APIs

Affected packages
py35-matrix-synapse < 1.5.0
py36-matrix-synapse < 1.5.0
py37-matrix-synapse < 1.5.0

Details

VuXML ID 42675046-fa70-11e9-ba4e-901b0e934d69
Discovery 2019-10-29
Entry 2019-10-29

Matrix developers report:

Make sure that [...] events sent over /send_join, /send_leave, and /invite, are correctly signed and come from the expected servers.

References

URL https://github.com/matrix-org/synapse/pull/6262
URL https://github.com/matrix-org/synapse/releases/tag/v1.5.0