Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Fix event filtering in get_missing_events handler #3371

Merged
merged 1 commit into from
Jun 8, 2018

Conversation

richvdh
Copy link
Member

@richvdh richvdh commented Jun 8, 2018

No description provided.

@dbkr dbkr merged commit ad9edd1 into develop Jun 8, 2018
neilisfragile added a commit that referenced this pull request Jun 8, 2018
Changes in synapse v0.31.1 (2018-06-08)
=======================================

v0.31.1 fixes a security bug in the ``get_missing_events`` federation API
where event visibility rules were not applied correctly.

We are not aware of it being actively exploited but please upgrade asap.

Bug Fixes:

* Fix event filtering in get_missing_events handler (PR #3371)
@carnil
Copy link

carnil commented Jun 13, 2018

CVE-2018-12291 has been assigned for this issue by MITRE.

@richvdh richvdh deleted the rav/fix_get_missing_events branch July 10, 2018 12:56
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants