PT-2020-16383 · Matrix+1 · Matrix Synapse+1
Erikjohnston
·
Published
2020-12-09
·
Updated
2024-06-15
·
CVE-2020-26257
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Matrix Synapse versions prior to 1.23.1
Description
A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of API endpoints such as
/send join, /send leave, /invite, or /exchange third party invite. This can lead to a denial of service in which future events will not be correctly sent to other servers over federation. The issue affects any server that accepts federation requests from untrusted servers.Recommendations
For versions prior to 1.23.1, update to version 1.23.1 to resolve the issue.
As a temporary workaround, homeserver administrators could limit access to the federation API to trusted servers, for example via
federation domain whitelist.Fix
DoS
Special Elements Injection
XSS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Matrix Synapse