Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Improper validation of receipts allows forged read receipts

Low
erikjohnston published GHSA-7565-cq32-vx2x Sep 26, 2023

Package

pip matrix-synapse (pip)

Affected versions

>= 0.34.0, < 1.93.0

Patched versions

1.93.0

Description

Impact

Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show the event as read by the user, even if they are not in the room.

Patches

#16327

Workarounds

There is no workaround.

Severity

Low

CVE ID

CVE-2023-42453

Weaknesses