Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Signature checks not applied to some retrieved missing events
Vulnerability Description
Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note that this does not apply to events retrieved through other endpoints (e.g. `/event`, `/state`) as they have been correctly verified. Homeservers that have federation disabled are not vulnerable. The problem has been fixed in Dendrite 0.9.8. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
Dendrite 数据伪造问题漏洞
Vulnerability Description
Dendrite是matrix基金会开源的一个用 Go 编写的第二代 Matrix 家庭服务器。 Dendrite 0.9.7及以前的版本存在数据伪造问题漏洞,该漏洞源于其使用“/get_missing_events”路径从远程主服务器检索到的事件没有正确验证其签名。这可能会允许远程主服务器通过这个端点向Dendrite提供无效/修改的事件。
CVSS Information
N/A
Vulnerability Type
N/A