Critical security vulnerability in Synapse 0.12 to 0.16.1 inclusive

We’ve been made aware of a critical security issue in Synapse present in versions 0.12 through 0.16.1 inclusive which can allow users’ accounts to be accessed by other unauthorized users on the same server. The issue was reported at 14:40 UTC on 2016-07-07 by Patrik Oldsberg at Ericsson (many thanks Patrik for discovering the issue … Continue reading Critical security vulnerability in Synapse 0.12 to 0.16.1 inclusive