Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers. Reference: https://github.com/matrix-org/synapse/pull/6262
Created matrix-synapse tracking bugs for this issue: Affects: fedora-all [bug 1770334]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.