CVE-2018-12291: Incorrect Default Permissions
(updated )
The on_get_missing_events
function in handlers/federation.py
in Matrix Synapse has a security bug in the get_missing_events
federation API where event visibility rules were not applied correctly.
References
Detect and mitigate CVE-2018-12291 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →