{"id":"GHSA-ch5v-fhg8-7gv9","summary":"Matrix Synapse Authorization Error","details":"In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no `m.room.power_levels` event in force.","aliases":["CVE-2018-12423","PYSEC-2026-844"],"modified":"2026-07-07T11:56:21.982919828Z","published":"2022-05-13T01:49:35Z","database_specific":{"github_reviewed_at":"2023-07-22T00:05:35Z","nvd_published_at":"2018-06-14T21:29:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12423"},{"type":"WEB","url":"https://github.com/matrix-org/matrix-doc/issues/1304"},{"type":"WEB","url":"https://bugs.debian.org/901549"},{"type":"PACKAGE","url":"https://github.com/matrix-org/synapse"},{"type":"WEB","url":"https://matrix.org/blog/2018/06/14/security-update-synapse-0-31-2"}],"affected":[{"package":{"name":"matrix-synapse","ecosystem":"PyPI","purl":"pkg:pypi/matrix-synapse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.31.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-ch5v-fhg8-7gv9/GHSA-ch5v-fhg8-7gv9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}