In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
2018-06-14T21:29:00.253
2024-11-21T03:45:11.783
Modified
[email protected]
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9