github.com
https://github.com/matrix-org/synapse CVE-2022-39374
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
Description
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
synapseBrowse matrix-org / synapse | CVE List | >= 1.62.0, < 1.68.0 | affected |
matrix-synapseBrowse PyPI / matrix-synapse | GitHub Advisory | 1.62.0 to < 1.68.0rc1 · Fixed in 1.68.0rc1 | affected |
References
7github.com
https://github.com/matrix-org/synapse/commit/b73cbb82157d9666e8d667733afebc0d09ed858c github.com
https://github.com/matrix-org/synapse/pull/13723 github.comConfirmation
https://github.com/matrix-org/synapse/security/advisories/GHSA-p9qp-c452-f9r7 github.com
https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2023-66.yaml lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJIJRP5ZH6B3KGFLHCAKR2IX2Y4Z25QD nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-39374