PT-2023-13719 · Synapse+3 · Synapse+3

Kasak

·

Publicado

2023-05-24

·

Atualizado

2025-04-22

·

CVE-2022-39335

CVSS v4.0

7.7

Alta

VetorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Synapse versions up to and including 1.68.0
Description The Matrix Federation API in Synapse allows remote homeservers to request authorization events in a room, which is necessary for validating the legitimacy and permission of events. However, in affected versions, a Synapse homeserver does not sufficiently check if the requesting server should be able to access these events. This issue can be exploited when a malicious actor knows the ID of a target room and the ID of an event from that room. The issue is of negligible consequence for public rooms and deployments in a closed federation where all homeservers are trustworthy.
Recommendations For Synapse versions up to and including 1.68.0, upgrade to Synapse 1.69.0 to resolve the issue. As a temporary workaround, consider configuring Synapse with a list of trusted servers using the federation domain whitelist to restrict access, but this is not practical for homeservers participating in open federation.

Exploit

Correção

Missing Authorization

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4748
CVE-2022-39335
GHSA-45CJ-F97F-GGWV
PYSEC-2023-65
USN-7444-1

Produtos afetados

Alt Linux
Linuxmint
Synapse
Ubuntu